AEPD (Spain) - PS/00552/2023
| AEPD - PS/00552/2023 | |
|---|---|
| Authority: | AEPD (Spain) |
| Jurisdiction: | Spain |
| Relevant Law: | Article 5(1)(f) GDPR Article 32 GDPR Article 33 GDPR Article 34 GDPR |
| Type: | Investigation |
| Outcome: | Violation Found |
| Started: | 01.04.2024 |
| Decided: | |
| Published: | 18.03.2026 |
| Fine: | 1,090,000 EUR |
| Parties: | AEPD CECOTEC INNOVACIONES, S.L.U. |
| National Case Number/Name: | PS/00552/2023 |
| European Case Law Identifier: | n/a |
| Appeal: | Unknown |
| Original Language(s): | Spanish |
| Original Source: | AEPD (in ES) |
| Initial Contributor: | Niovi Gkioka |
The DPA fined an e-commerce company €1,090,000 after a breach of a database connected to its unused legacy system led to millions of data points being disclosed on the dark web.
English Summary
Facts
CECOTEC INNOVACIONES, S.L.U. (the controller) operated an e-commerce platform used to manage customer orders and accounts. In early 2021, it decommissioned the platform but kept the legacy system accessible for internal purposes.
On 5 April 2023, the Instituto Nacional de Ciberseguridad (INCIBE), Spain's national cybersecurity institute, informed the controller that a database allegedly belonging to it, containing over one million records, was being offered for sale on the dark web.
On 12 April 2023, INCIBE sent a second notification, after which the controller carried out an internal investigation. The controller questioned the existence and scope of the breach, arguing that only a limited number of records matched its database and that it could not confirm unauthorised access. It considered the risk to be low. On 19 April 2023, it notified the Spanish Data Protection Authority (AEPD) but did not inform affected data subjects.
The AEPD carried out preliminary investigations and, on 1 April 2024, initiated sanctioning proceedings. It found that the data originated from the controller’s database and that the legacy system remained accessible via the internet, relied on outdated software and lacked adequate monitoring, logging and access control measures.
Holding
First, the Spanish Data Protection Authority (AEPD) held that storing personal data in a legacy system that remained accessible and relied on outdated software without adequate security measures infringed Article 5(1)(f) and Article 32 GDPR.
Second, the AEPD held that a controller cannot delay breach notification on the basis of uncertainty as to the existence or scope of a breach and must act upon reasonable indications of compromise. The controller therefore infringed Article 33 GDPR by failing to notify the authority within 72 hours.
Third, the AEPD held that the failure to inform data subjects constituted an infringement of Article 34 GDPR, as the breach involved a large volume of personal data and potential risks could not be excluded.
The AEPD fined the controller €1,090,000.
Comment
In a related development, in April 2025 consumer association FACUA filed a separate complaint with the AEPD against CECOTEC, criticising the company for only notifying affected customers of the breach nearly two years after it occurred. No outcome of that complaint has been reported as of March 2026.
Further Resources
Share blogs or news articles here!
English Machine Translation of the Decision
The decision below is a machine translation of the Spanish original. Please refer to the Spanish original for more details.
1/173
• File No.: EXP202305790
Disciplinary Proceeding No. PS/00552/2023
- RESOLUTION OF SANCTIONING PROCEEDINGS
From the proceedings initiated by the Spanish Data Protection Agency and based on the following:
BACKGROUND
FIRST: On April 19, 2023, the Technological Innovation Division of this Agency was notified of a personal data breach by the data controller, CECOTEC INNOVACIONES, S.L.U., with Tax Identification Number (NIF) B97937890
(hereinafter, the company), concerning the exfiltration and sale online of a database containing personal data of clients and employees with more than 1 million records, detected on April 5, 2023, by the Spanish Cybersecurity Institute (INCIBE).
The following key information is revealed in the breach notification:
- Incident Summary:
The company received a notification from INCIBE on April 5, 2023, informing them that
a malicious actor had posted on a dark web forum
claiming to possess a database belonging to a Spanish company with
approximately 1 million records. The company's name was not mentioned, but
based on various details provided, it appears to be their
company. INCIBE alerted them to this post and requested that they
verify the cyberattack on their database, providing 17
data records posted by the malicious actor as a sample.
The company was unaware of the notification sent until it received a
second notification from INCIBE on April 12, 2023, informing its
Data Protection Officer of the incident and initiating an investigation
on April 14, 2023, which did not conclude until April 17, 2023, the date on which the Data Protection Officer informed
INCIBE that it did not believe the attack was viable and, if so, genuine,
having detected only 6 real records out of the 17 submitted that
belonged to a company database that was closed in 2021, to which
only employees have access. It was also indicated that the
company had taken security measures regarding the database,
reinforcing its access and usage limits.
- The breach affects the following types of data: “Basic data (e.g., name, surname, date of birth), National Identity Document (DNI), Foreigner's Identity Number (NIE), Passport, and/or any other identification document, Contact information”).
- The data controller states that the identified personal data is located on a data platform that was closed in 2021, but which employees can access to consult matters related to clients and orders.
28001 – Madrid 6 sedeagpd.gob.es 2/173
- Affected parties: 6 data subjects. The data was not encrypted.
- The breach is classified as a confidentiality breach of low severity.
- The incident occurred due to a failure, deficiency, or non-compliance with implemented security measures: Unknown
- It has not been reported to the authorities.
- New measures have been adopted following the breach, but these are not detailed.
- The affected parties will not be notified.
- It considers that it has taken all possible actions and considers the breach resolved.
SECOND: On May 3, 2023, the Director of the Agency ordered the General Sub-Directorate of Data Inspection to carry out the appropriate preliminary investigations in order to determine both the occurrence and scope of the reported confidentiality breach, as well as the possible liability of the company CECOTEC for a possible breach of its obligations as the data controller responsible for the protection of personal data contained on said platform, given that:
- There are doubts about the veracity of the cyberattack denied by the defendant, as well as
the occurrence of a confidentiality breach, and its severity or
number of affected parties, since the data controller states that it gives no credence
to the cybercriminal's announcement, despite acknowledging that
6 real data points have been identified out of the 17 records published in the sample, which
correspond to data located on a platform belonging to the data controller.
Furthermore, it is necessary to specify the type of personal data affected, since
it is only indicated that the breach affected: “basic personal data (e.g.,
name, surname, date of birth), National Identity Document (DNI), Foreigner's Identity Number (NIE), Passport, and/or any
other identification document, Contact Information.” And which of these are
test data or real data.
- There are doubts about the failure to notify the
affected parties of the breach, since the responsible party states that the breach affects
the confidentiality of the data and that the data was not encrypted,
anonymized, or otherwise protected to prevent the data subjects from
being identified. However, they have not informed them of the potential breach, not even
these six actual cases detected.
- There are doubts about the security measures in place prior to the incident, given that
the responsible party states that a platform shut down in 2021 continues to be used, and that
it contains more than one million data records, including
personal data of clients and employees. Since this is a platform
classified by the data controller as “closed,” there are doubts about whether
security updates are being applied to the platform, and whether it has
the appropriate security measures in place to protect traceability,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 3/173
availability, and confidentiality.
- There are doubts about the adoption of security measures prior to the
incident if a new platform has been used since
2021, to which the data has been migrated, since this migration
requires additional measures for the protection of personal data that
need to be verified.
- There are doubts about the security measures prior to the incident because
the data controller stated that test data could be stored alongside real data still in use in the same database on a closed platform.
- For all the above reasons, doubts also exist regarding compliance with the
obligation of the data controller to process data in a manner that guarantees its
confidentiality.
THIRD: Following the opening of investigation proceedings under number AI/00150/2023, the
Sub-Directorate General for Data Inspection proceeded to carry out preliminary investigative actions to clarify the facts in question, and by virtue of
the functions assigned to supervisory authorities in Article 57.1 and the
powers granted in Article 58.1 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR), and in accordance with the provisions of
Title VII, Chapter I, Section Two, of the LOPDGDD, it issued
various requests for information and verification procedures, which will be referred to below.
FOURTH: On August 4, 2023, the Spanish Data Protection Agency (AEPD) issued its first request for information to the company—notified to the company on August 8, 2023—requesting that it provide the Agency with the requested data and documents, and the actions taken to comply with the requirements of data protection regulations.
On August 30, 2023, the Agency received its first written response to the request, stating the following:
1. Regarding the processing activities affected by the breach and the Record of Processing Activities (ROPA):
It is stated that the platform affected by the incident was the company's former online store, based on software ***SOFTWARE.1, and that it had been migrated to a new platform that provided continuity with the previous one.
The activities affected by the breach are:
• Activity “Customer Management” with the following data incorporated into the RAT:
• Purpose: to manage orders through the website. To address customer queries and complaints. To manage returns and order cancellations. To send commercial communications to customers.
28001 – Madrid 6 sedeagpd.gob.es 4/173
• Activity start date: 2013.
• Data affected: Name and surname, NIF (Spanish Tax Identification Number), email, telephone, and address.
• Transfers: Data may be transferred using Standard Contractual Clauses approved by the EC.
• Retention period: This is determined by the statute of limitations for legal actions under the Consumer Protection Act.
• Security measures: (...).
• Legal basis: contract, compliance with legal obligation (Consumer Protection Act), legitimate interest.
• Other affected activities, for which information is also included in the RAT:
• Newsletter distribution: activity began in 2015.
• Web user accounts: with activity starting in 2013.
• HR Management (they confirm the existence of an affected employee who appeared in the sample published by the attacker): activity starting in 2014.
2. Regarding the affected platform, it is stated: “The platform was designed as an online store using ***SOFTWARE.1 software, dedicated to the creation and management of virtual stores for e-commerce.”
This platform was hosted on the ***PLATFORM.1 infrastructure and was configured to have no direct internet exposure, thus ensuring that all personal data remained secure and accessible only to internal components of the platform.
They state that “The platform was replaced by a new online store
developed internally that adopted more modern open-source web development technologies
This transition was completed in early 2021.
Despite the closure of the original platform, limited access to it (its ***INTERFACE.1) has been maintained for the sole purpose of addressing requests,
needs, and/or complaints from the company's customers.”
Therefore, at the time of the breach, ***INTERFACE.2 (…) of this platform was not
operational, with only ***INTERFACE.1 remaining active
(…), which allows adding/editing/deleting products and managing customer data.
3. Regarding the data affected by the personal data breach.
It is stated that on the affected platform: “A variety of
personal data that were essential for the operation and management of the
online store are stored; however, in the context of the possible incident reported by
INCIBE, the allegedly affected data relates to table
TABLE.1 within the database.”
The affected data, according to the screenshot published by the cybercriminals,
were: city, postal code, secondary postal address, notes on the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 5/173
postal address, primary and mobile phone numbers, national identity card number (DNI), and tax identification number.
4. Regarding the sample published by the cybercriminals, the following is stated:
An internal email is provided in which the cybersecurity department makes the following statement regarding the data contained in the screenshot posted on the forum:
After conducting the analysis, it was observed that the records in the table match those of the company's old store. After investigating with the e-commerce and infrastructure departments, we were able to see that the attacker's records span from 2016 to 2020, assuming they have the 1,000,000 records they claim, since only 18 records are shown in the attached image. This table contains user data such as addresses, postal codes, cities, phone numbers, email addresses, etc.
5. Regarding the users who had access to this platform, they state that:
- “Users who had access to the platform's administration before its closure (…). In turn, each of these departments had specific permissions assigned according to their role in the online store's operation.”
- “Regarding the assignment of roles and access permissions to the platform, at that time there was no formalized procedure for this task. The structure of users, roles, and their permissions was configured in a relatively simple way because, at that time, the company had a relatively small number of employees. It operated as follows: The heads of the different departments communicated to the IT Department the specific permissions that each user needed, and IT proceeded to assign them according to the instructions.”
- It is stated that after the alleged incident, significant measures were taken to strengthen the platform's security: (…).
6. Regarding the measures in place to ensure traceability on the platform, the following statements are made:
- The company indicates that “before receiving the notification from INCIBE, the platform already had robust measures in place to ensure the traceability of actions accessing both the platform and the database management system. These measures were designed to guarantee data security and integrity, as well as to detect any suspicious activity early.”
However, this response contrasts with the statement made by the cybersecurity department itself
in one of the internal emails submitted in the
investigation, where it stated the following: “We tried to view the logs to trace
the attack and uncover the attacker, but we couldn't get anything clear, since
we saw the logs for ***SOFTWARE.1 and they weren't very useful because they only
showed user logins. Furthermore, due to
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 6/173
performance issues, some logs recorded by the CMS were deactivated and were not
reactivated later. We also saw that said ***SOFTWARE.1
had several version vulnerabilities, but we can't determine if
that's the entry vector.”
- Regarding the database management system, they claim there were
measures restricting direct internet access and logs
monitoring access and activity in the database, but these are neither detailed
nor substantiated.
7. Regarding the circumstances of the incident and the certainty of the attack on the
company.
- An Excel spreadsheet containing the documented record of the incident is provided,
which states that the company does not believe the attack was real,
although it does state: “The security officer confirmed that
the INCIBE email was not a phishing attempt, and therefore, on April 17th at
11:48 AM, the institute was contacted and confirmed that same day that the
information sent was correct. The company has not been able to identify
how the malicious actor gained access to the company's systems.
Although the attacker claims to possess 1 million records, the
company can only access 17 of them. The platform has more than
1 million records, so it does not match what the
cybercriminal published.”
- Based on this, the DEP report of April 19, 2023, which led to the notification of the breach to this Agency, is provided. The report states that as of April 19, 2023, the company could only confirm that they had not been able to identify any suspicious access to internal systems and that the number of records the cybercriminal claimed to have did not match those existing in the databases. A detailed assessment of the incident was carried out, concluding with a MEDIUM severity or impact and a LOW probability of occurrence, and therefore recommending that the incident be reported to the Spanish Data Protection Agency (AEPD).
However, the conclusion reported by the company to INCIBE and this Agency
does not coincide with that given by the company's cybersecurity manager to
the Data Protection Officer (DPO), who sent an internal email to the DPO on April 15, 2023, stating
that he could not clearly determine the source of the attack, as he did not have
any system for monitoring equipment on the attacked platform.
We are referring to the internal email sent from address ***EMAIL.1 to address
***EMAIL.1 on April 14, 2023, providing information about the incident,
which states:
“After analyzing the logs of the image posted on the
forum, it was found that they match those of the company's old online store
(…) which was closed in 2021 but is still used by some people
for browsing purposes.”
“We also tried to view the logs to trace the attack and identify the attacker, but we couldn't get anything clear since they only showed user logins. Furthermore, some logs were disabled at the time due to performance issues.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 7/173
We couldn't see much at the server and database level since it wasn't being monitored.
We also saw that the ***SOFTWARE.1 had several version vulnerabilities, but we can't determine if that was the entry point.”
“After analyzing all environments, the cybersecurity department cannot determine whether the breach was caused by malware on a workstation or by the web application itself, since we currently have no system for monitoring devices on the workstation, and the web application is not monitored.”
- It is also stated that the company has taken the following measures: (…).
- The additional measure taken is (…). There is no evidence of damage caused to potentially affected clients.
8. In response to our request for proof of risk analyses of the processing activities affected by the breach.
Attached is a copy of the final risk analysis report for the rights and freedoms of individuals affected by the processing activities related to the breach (customers), dated April 10, 2022.
This report states that: “For reasons unknown, a joint risk analysis was carried out for the processing of data related to Customers and Suppliers, HR Management, and Recruitment, and is attached.”
The inspector's analysis of this document reveals that the Risk Analysis Report is dated April 10, 2022, and therefore does not address risks prior to that date. It contains the following sections:
• A section describing the three processing activities affected by the analysis: “Customers and Suppliers,” “Recruitment,” and “Human Resources Management.”
• It contains a section “Identification and Analysis of Risk Factors (inherent and residual)” which refers to Annex I, which is not provided.
• It contains a section where a value is assigned to the probability and
impact for the following identified inherent risks: making
international transfers to countries without adequate regulations, not providing
information correctly, storing data for longer
periods, lacking control mechanisms for the relationship with
processors, and deficiencies in storage protocols in
physical format.
• It contains a section with an action plan that incorporates the
following control measures: (...).
9. Regarding the retention periods for personal data of the
affected activities, they state that these are:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 8/173
• Up to 9 years based on the statute of limitations for actions concerning
consumers and users.
• Up to 4 years in accordance with the General Tax Law.
or Up to 5 years general statute of limitations for actions that do not have a specific time limit, Article 1964 of the Civil Code.
or Up to 6 years based on Article 30 of the Commercial Code.
10. Regarding the preventive measures implemented:
(…)
11. In response to our request for proof of the procedures
implemented in the organization to manage security breaches that
affect personal data.
It is stated that a new version of this procedure has been drafted and
has been made known to employees. A screenshot of
an internal email informing about this is provided; however, no supporting documentation is provided. Only a screenshot of an internal email sent on
August 10, 2023, with the following text is provided: “(…)”.
They state that in recent months (…), and screenshots
of activities carried out on May 11 are provided. June 27, 2023.
It is claimed that the Cybersecurity Officer has developed an
internal tool with which employees can (…). This is not substantiated.
12. Regarding the justification for the reason they reported the personal data breach outside the deadline.
The company states that it was not until Thursday, April 13, 2023, that INCIBE provided all the information regarding the possible breach and, therefore,
when they became aware of the possible leak and the screenshots
published by the hacker. They also state that they did not respond within the maximum 72-hour period
because this period expired outside of working hours, since Monday, April 17,
2023, was also a public holiday and a non-working day in Quart de Poblet
(the municipality where the company's headquarters were located at the time of the
incident management).
FIFTH: On September 4, In 2023, a new request for information was made to the data controller at the company to expand upon the documentation provided. This request was answered on September 18, 2023, as follows:
1. Confirmation of whether risk analyses existed prior to April 10, 2022,
as well as any subsequent updates following the breach.
It was confirmed that no analysis prior to this date existed.
28001 – Madrid 6 sedeagpd.gob.es 9/173
2. The document referenced in the risk analysis, which was not located in the previous response, was provided.
An Excel document containing the file referenced in the risk analysis of April 10, 2022, and not located in the response to the previous request, was provided.
However, no additional information was obtained regarding the analysis. An Excel file with the updated risk analysis following the security breach was also included.
3. Proof of the internal procedure implemented for the Security breach management
The following statement is made: “The Spanish Data Protection Agency (AEPD) is informed that, in the last year,
the position of Data Protection Officer has been held by three
different people, resulting in a lack of continuity in the functions of the Data Protection Officer
as specified in Article 39 of Regulation
2016/679 of 27 April 2016 (hereinafter, “GDPR”). Therefore,
the company is currently in an urgent review process of
documents and is deciding on measures to take and procedures to
implement, including a review of all
risk analyses performed and an assessment of the need to conduct an impact
assessment of these analyses.”
It is stated that a Security Committee was established on September 14, 2023,
to dictate measures.
An internal document is provided, which the company claims are
fact sheets containing the Internal Security Breach Management Plan.
This document lacks a signature and creation date, only a “last update date
(…)”. Another document, called the Security Breach Management Protocol, is also included. This unsigned document contains only the
following text at the end: “Last update date (…)”.
Regarding the version of ***SOFTWARE.1 used by the platform
(1.6.1.24), the company states: “Regarding the Regarding version 1.6.1.24 of the platform
of ***SOFTWARE.1 (hereinafter, “the platform”), it is important to note
that, although this version contains known vulnerabilities (CVEs),
most of these affect ***INTERFACE.2 (…) and, as we indicated in
our response to the previous request, ***INTERFACE.2 (…) is not
active. Only ***INTERFACE.1 of the platform is active, and it also has a data access level applied. As for
the vulnerabilities that affected it, these have already been identified and
addressed with the appropriate security measures, in accordance with what
was established in our first response.
It is acknowledged that the reason the platform is still accessible on
the Internet is that the migration of integrations from
the old platform to the new one has not yet been completed. They state that ***INTERFACE.1 remains active
because: “(…). Furthermore, some of these integrations still require
28001 – Madrid 6 sedeagpd.gob.es 10/173
that the platform's ***INTERFACE.1 be accessible from the Internet. However,
in the coming months (…)”.
4. Request information regarding possible communication with the individuals affected
by the breach.
The company states that “the individuals
potentially affected by the attack have not been informed, without prejudice to the possibility that in the future
this entity may become aware that the exfiltration is, in any case,
real; in which event, the required communication and information will be provided to
the affected individuals.”
They also state (…) without detecting any purchase, sale, or activity involving the
allegedly affected data.
SIXTH: On August 4, 2023, in order to verify the veracity of the information published in the forum and the leak of personal data of the company's clients, the inspector contacted the forum user who posted the message with the sample, claiming to possess this database. The user responded, confirming that the database belongs to the company and contains 1,086,185 records with client data and 837,606 unique mobile phone numbers. The user also provided a new sample containing up to 7,000 personal data records of 1,000 affected individuals or different data subjects, organized by tax identification number (NIF).
This sample and the communications between the cyber attacker and the inspector were included as evidence in the Investigation Report of December 1, 2023, which will be discussed later.
SEVENTH: On November 2, 2023, the file was added to which the inspector's access report to the defendant's platform was added. The report states that on that date, the inspector accessed the URL provided in the screenshots of previous emails (exchanged with INCIBE), which corresponded to the access address of the old platform based on ***SOFTWARE.1 (and the possible origin of the attack). The report confirmed the following:
- That access to the URL ***URL.1 remains available, allowing access to
***SERVICE.1 of the ***SOFTWARE.1 software installation.
- It has been verified that the version of ***SOFTWARE.1 used is version 1.6.1.24,
and by checking the status of this version on the open-source code's website,
it is concluded that it is a rather obsolete version, unsupported since
June 2019, with multiple vulnerabilities (both in ***SERVICE.2 and
in ***SERVICE.1) that require updating to later versions as a solution.
EIGHTH: As a result of these actions, on December 1,
2023, a Preliminary Actions Report was issued by the inspector in charge of the
investigation file, which included the documentation obtained during the
proceedings carried out by the investigating officer on August 4 and November 2 at
28001 – Madrid 6 sedeagpd.gob.es 11/173
referenced above, as well as the company's requests and
responses and other documents contained in the file.
Based on the actions carried out, the Report issued the following
CONCLUSIONS:
1. Regarding the attack vector, it could not be determined whether it was caused by
malware on a workstation or through the software application used
for the company's former online store platform. However, it has been
confirmed that this platform was based on an obsolete and
outdated version of the software ***SOFTWARE.1, with known vulnerabilities,
which had been out of support since 2019, and that it had an administration section
(***SERVICE.1) with public access via the internet (although restricted by username
and password).
2. Regarding the detection and notification of the breach, the company
became aware of it following an email notification received from
INCIBE on April 5, 2023, alerting them to the possible sale and leak of this
organization's data through a forum on the dark web. Regarding the timeline, it is
established by the provided emails that the first warning of the
breach/cyberattack occurred on April 5, 2023, but the company did not acknowledge it until
a second warning was issued on April 12, 2023. They finally responded to INCIBE on
April 17, 2023, and notified the Spanish Data Protection Agency (AEPD) of the breach on April 19, 2023.
3. The company denies that the leak is real, stating
that the forum post never mentions that the database
belongs to this organization and, furthermore, that the 17 sample data points
contained in the published screenshot are insufficient to
determine that there has been an actual leak of the company's database.
However, they acknowledge that these test records match data
stored in one of their database tables.
4. The inspector contacted the user who claimed to be selling the alleged database to verify the information and confirm the existence of a personal data leak. The user confirmed that the database referenced in the message belongs to the company and contains 1,086,185 records with customer data. The user provided the inspector with a new sample containing 1,000 records (personal data of 1,000 different data subjects), in addition to the 17 published in the sample, with the same field and data structure as the published screenshot. Regarding this field structure, the company had
confirmed that it corresponds to the table “***TABLE.1” in its database, which
contains the following personal data of 1,000 people: “***TABLE.12,
postcode, city, other, phone, mobile_phone, VAT_number, ID_number.
5. Regarding the preventive measures implemented before detecting the
security breach to guarantee the security of personal data processing
by the former online sales platform, it has been found that:
- The logs of this platform (based on ***SOFTWARE.1) (…), therefore, were not
useful for identifying and detecting the potential attack, also due to
28001 – Madrid 6 sedeagpd.gob.es 12/173
performance issues (…), lacking adequate measures to guarantee
traceability at the time the breach occurred.
- This platform, despite being old and undergoing migration, was
It remained active, providing direct internet access only to the
***SERVICE.1 portion (they claim this was necessary due to integration requirements with the new platform).
- Furthermore, it has also been established that the old platform used
version 1.6.1 of ***SOFTWARE.1, which has been found to be
an outdated version, unsupported since 2019 and
with multiple critical vulnerabilities affecting both ***SERVICE.2 (…)
and ***SERVICE.1 (…).
- Moreover, it has been established that the following preventive measures were in place:
(…)
6. After detecting the security breach, the following reactive measures were adopted to strengthen the platform's security:
(…)
7. It has been established that the incident was not communicated to the individuals
affected by the breach (or potentially affected). The company maintains that this communication is unnecessary, claiming that they do not believe that
the leak was real, only having certainty of the leak of some
records shown in the screenshot posted on the forum.
8. Regarding risk analyses, the existence of a documented
analysis carried out on April 10, 2022, has been verified. The company
confirms that there are no risk analyses dated prior to the aforementioned date; however, it has been established that the processing activity
affected by the breach began in 2013 (“Customer Management”).
NINTH: The Axesor Report on the company's business activity, dated December 1, 2023, is obtained and added to the file. This report indicates that the entity
under investigation has the following business volume, according to Axesor data as of 2022:
a. (…)
TENTH: On December 1 In April 2024, the Director of the Spanish Data Protection Agency agreed to initiate sanction proceedings against the accused party, in accordance with the provisions of Articles 63 and 64 of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), for the alleged commission of four administrative infringements classified under Article 83.4 and Article 83.5 of the GDPR, punishable by the following fines:
- For the infringement of Article 5.1.f) of the GDPR, a fine of €140,000.
- For the infringement of Article 32 of the GDPR, a fine of €750,000.
- For the infringement of Article 33 of the GDPR, a fine of €100,000.
- For the infringement of Article 34 Under the GDPR, a fine of €40,000.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 13/173
ELEVENTH: Having been notified of the aforementioned initiation agreement in accordance with the rules established in Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter, LPACAP), the accused party submitted a request for an extension of the deadline and a copy of the file dated April 12, 15, and 17, 2024.
On April 18, 2024, an agreement was issued extending the deadline and sending a copy of the file to CECOTEC. This agreement states that the copy of the file will be sent to CECOTEC's postal address in USB format, given that its size exceeds the maximum allowed for electronic notification. The
notification of said extension and copy agreement and of the document containing the keys
necessary to open the attached file occurs on 19/04/2024 electronically, although
the notification of the copy of the file by mail does not occur until
30/04/24.
On April 25, 2024—having received notification of the extension of the deadline and the forwarding of a copy, but not yet having received the file sent by mail—CECOTEC submitted its first statement of objections to the initiation agreement (hereinafter, Objection AI #1).
This first statement of objections to the initiation agreement does not include any documentation
and requests the dismissal of the file and the opening of a new period for objections,
stating, in summary, the following:
or PRELIMINARY. VIOLATION OF THE LEGALLY
ESTABLISHED PROCEDURE. INFRINGEMENT OF ARTICLE 24 OF THE SPANISH CONSTITUTION.
It states that it has not received a copy of the file, alleging
that this lack of access to it results in a lack of due process, constituting nullity
by operation of law due to the absolute absence of the procedure. Therefore,
by means of “FIRST ADDITIONAL CLAUSE,” they request that a period for supplementary objections be opened.
FIRST.- VIOLATION OF THE NE BIS IN IDEM PRINCIPLE BY
SANCTIONING THE SAME CONDUCT TWICE WITH RESPECT TO THE
INFRINGEMENTS CONTEMPLATED IN ARTICLES 5.1. F) AND 32 OF THE
GDPR.
They express their disagreement with the classification of the facts made
by the Spanish Data Protection Agency (AEPD) within the scope of Article 5.1. f) and Article 32. Article 32 of the GDPR, since
it implies penalizing the same conduct twice, based on the following:
or In accordance with Guidelines 04/2022 of the European Data Protection Board,
or European Data Protection Board (hereinafter, “EDPB”) on
the calculation of fines under the GDPR, the provisions invoked by the
Spanish Data Protection Agency (AEPD) in this sanctioning proceeding would protect the same
legal interest, namely, the adequate security of personal data,
and it is therefore illegal to penalize the offender twice for the same offense. In this regard, we must cite the Judgment ‘Austrian
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 14/173
Verwaltungsgerichtshof’, Ra 2018/02/1023, paragraph 7.
CECOTEC then goes on to point out that: “In the present
case, the protected legal interest (data confidentiality)
is the same. The Spanish Data Protection Agency (AEPD) focuses both infringements on the fact that
adequate technical and organizational security measures have not been adopted, which
has affected the ability to guarantee confidentiality,” which
implies violating, according to the EDPB Guidelines, “the ‘principle of
consumption’ or that one infringement is a precursor to the other.”
Furthermore, in this party’s opinion, there would be a violation of the principle
of ‘ne bis in idem’, according to the criteria of the National Court (by All:
Judgment of the National Court of July 23, 2021 (appeal no. 1/2017).
Also cited is the Order of the Supreme Court (Administrative Chamber), Section 1, A
July 13, 2023, appeal no. 3120/2023.
The application of the Principle contained in Article 29 of Law
40/2015, of October 1, on the Legal Regime of the Public Sector (hereinafter, the “LRJSP”) is alleged: 5. When the commission of one infringement necessarily leads to the commission of another or others, only the sanction corresponding to the most serious infringement committed shall be imposed.
SECOND. – ABSENCE OF CULPABILITY OR GROSS NEGLIGENCE
WITH RESPECT TO THE INFRINGEMENTS CONTEMPLATED IN ARTICLES 5.1. F)
AND 32 OF THE GDPR.
“It is important to emphasize that the security breach reported on April 19, 2023, occurred on the CECOTEC platform not due to a lack of security measures or their ineffectiveness, but rather due to an attack by a third party (hacker) who gained unauthorized access to the system. In this regard, we cite the Judgment of the National Court (Administrative Chamber), Section 1, dated November 10, 2017, Appeal No. 32/2016.”
(Note: The original text incorrectly states that the breach occurred on April 19, 2023, and is not relevant to the preceding text.) Regarding the CECOTEC platform, which, as has been proven, was illegally accessed by a third party, we must emphasize,
as has been reported to the Spanish Data Protection Agency (AEPD) during the preliminary investigations,
that technical and organizational security measures were in place to prevent unauthorized access by third parties,
such as access controls.
Regarding this platform, we inform the AEPD that it has been disabled and disconnected from the internet.
CECOTEC does not process data of a special category or of greater sensitivity on the platform, nor does it process data concerning minors.
The existence of vulnerabilities mentioned in the document relating to the Initiation Agreement does not necessarily imply a breach of the security measures,
given that total security does not exist and that the obligation to ensure information security is not one of
results but rather an obligation of means. In this regard, our
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 15/173
Supreme Court, in Judgment 188/2022 of February 15, 2022.
On the other hand, an unauthorized disclosure of personal data or
unauthorized access to such data by third parties is not
sufficient, in itself, to consider that the technical and
organizational measures adopted by the data controller were not
appropriate under the aforementioned Articles 24 and 32. Rather, it is
necessary for the administration to demonstrate that there is a certain degree of
intent. Indeed, the
Court of Justice of the European Union (hereinafter, “CJEU”) has ruled in this sense
through its judgment of December 14, 2023, in
Case C-340/2021. And Spanish case law, in judgments
such as the Constitutional Court Judgment No. 76/1990 of April 26, or the Judgment of the Administrative Chamber
of the National Court, Section 1,
of December 23, 2013, Appeal No. 341/2012:
That there is no evidence—beyond mere indications—that allows
it to be proven that more than 6 actual users have been affected.
Some of the security breach cases that
were closed by this Agency are cited, such as the one suffered by Facebook in
2019, the Decathlon breach, or the Iberdrola breach in 2022.
THIRD. - LACK OF EVIDENCE THAT THE MEASURES ARE
INEFFECTIVE.
It is noted that the presumption of innocence and the "In dubio pro reo" principle must be applied,
given the serious doubts that the measures adopted by
CECOTEC were ineffective and the database targeted by the cyberattack
was CECOTEC's. Given that the administration is applying a
strict liability that does not exist, since the initial agreement is based
on indicators such as the number of platform users and in light of the
evidence presented, reasonable doubts exist.
FOURTH. - NON-EXISTENCE OF THE INFRINGEMENT OF ART. 33 GDPR REGARDING
THE NOTIFICATION OUTSIDE THE 72-HOUR DEADLINE.
or “The email sent to CECOTEC by INCIBE on April 13, 2023, indicates
that it cannot determine whether the information is truthful and whether it has been
exposed in other leaks. The table with information only contains
postal address, mobile phone number, and national identity card number. No names and surnames were affected, as stated in the agreement to initiate the sanctioning procedure.
And this situation of uncertainty persisted over time,
so that, with the data available to both INCIBE and CECOTEC at the time of the breach (April 2023), there was no real obligation to notify the breach, since there was only certainty of 6 actual individuals affected.
According to the AEPD guidelines, this did not imply an obligation to notify, and yet CECOTEC decided
to proactively notify.
It is not mandatory to notify all personal data breaches,
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 16/173
given that the GDPR provides an exception to this obligation when the controller can guarantee that the personal data breach is unlikely to pose a risk. Therefore, considering
the type of data affected, already mentioned, in which there were no data The fact that only six real people were identified by name and surname and were affected made the existence of a risk unlikely.
In this regard, it is worth recalling the criteria of the former Article 29 Working Party, which, in Guidelines WP250, determines when a risk is likely to occur.
The fact that the information was initially only used to identify the individuals involved made it unlikely.
The calculation of the starting date used by the Spanish Data Protection Agency (AEPD) to determine the 72-hour period, that is, April 17, 2023, is entirely arbitrary, since at that time,
CECOTEC was not in a position to, or had actual knowledge of, that a data breach had occurred.
FIFTH. - NON-EXISTENCE OF THE INFRINGEMENT OF ARTICLE 34 GDPR.
NOTIFICATION TO DATA SUBJECTS.
There is no infringement, given that it has not been proven that the security breach suffered by CECOTEC posed a "high risk" to the rights and freedoms of the data subjects, with the consequent obligation to notify them, beyond the subjective assessment carried out by the investigating officer.
CECOTEC initiated the appropriate checks from the moment it became aware of the INCIBE email and contacted them by telephone.
Although initially there were doubts about the veracity of the breach, it was ultimately reported to the Supervisory Authority as information was obtained.
Within this framework, an internal assessment of the “high risk” was carried out based on the objective information available at the time the breach was discovered, taking into account the factors indicated in Guidelines 9/2022 on the notification of personal data breaches under the GDPR, dated March 28, 2023.
Regarding the nature, sensitivity, and volume of the personal data:
These were incomplete contact details and not of a special category.
Regarding the volume of data:
Only six pieces of data belonging to real individuals were verified. -Regarding the ease of identifying the individuals: It was
complex given that the names and surnames of the
interested parties were not included, nor was there any associated documentation.
-Regarding the type of breach: It affected the confidentiality of the data
by an unauthorized third party, but not other areas such as
availability and integrity.
-Regarding the severity of the consequences for the individuals: It was
considered not to be serious given that the data is not of a special category
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 17/173
identity theft is neither automatic nor simple since
the names and surnames of those affected are not included, nor is it
proven.
-Regarding the characteristics of the individuals: They were not vulnerable
subjects nor minors.
Following this internal assessment and in accordance with the results of the
COMMUNICATE BRECHA tool provided by the Spanish Data Protection Agency (AEPD), CECOTEC did not deem it necessary to report the breach.
It is also intended to avoid the “unnecessary notification fatigue” referred to in the
Guidelines 9/2022 on the notification of
personal data breaches, which indicate that the threshold for reporting the
breach to individuals is higher than for notifying supervisory authorities.
Finally, the AEPD, based on the corrective powers it has
under Article 34.4 of the GDPR, should have indicated to CECOTEC
during the preliminary actions phase or when notifying them of the agreement to initiate
this procedure that they should proceed with notifying the
data subjects of the breach, if it considered it mandatory. And it is stated that: “this party fails to understand that this order has been issued in other proceedings
before the Spanish Data Protection Agency (AEPD) – as evidenced, among others, by the
resolution dated February 17, 2022, issued in PS No. E/06660/2021
or in the preliminary investigation files E/06214/2020 and
E/06177/2020, and that in the present proceedings, the possibility of offering CECOTEC prior consultation has been completely ignored,
opting instead
for the initiation of this Commencement Agreement.”
SIXTH. - LACK OF PROPORTIONALITY IN THE IMPOSITION OF SANCTIONS AND ABSENCE OF GRADATION.
o The Spanish Data Protection Agency (AEPD) is hereby informed that the platform
‘***SOFTWARE.1’ is completely disabled, and data processing has ceased.
o No mitigating circumstances are considered:
CECOTEC has not obtained any benefit; there is no evidence of repeated conduct, prior incidents, or intent to cause harm on the part of
CECOTEC; furthermore, no damages have been proven, nor is there a report on potential damages, nor are there any claims from any user; the breach does not affect special category data or data of minors. The corrective measures adopted by CECOTEC have not been assessed, as they were not requested or required by the AEPD, pursuant to Article 83, paragraph 2, letter i).
In general, there is a clear lack of proportionality in setting the amount of the
sanction: the fact that the maximum quantitative limit is so broad does not justify this
amount, which must be adjusted to the economic capacity and is considered
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 18/173
disproportionate according to jurisprudence and Article 29 of the LRJSP.
Several judgments are cited, such as the Supreme Court ruling of June 2, 2003, and the Supreme Court ruling of July 29, 2014 (Administrative Law Chamber, Section 1).
With respect to each infraction, the imposed fine is considered disproportionate because the following circumstances were not taken into account:
a. Regarding the imposed sanctions of €140,000 for the infringement of
Article 5.1.f) of the GDPR and €750,000 for the infringement of Article
32 of the GDPR, they are entirely disproportionate given
the lack of evidence that any damage has materialized and
that there is no complaint or claim from any user, coupled with the fact that
the accessed data of the 6 actual users would not currently allow
identity theft, as the
complete ID/Tax Identification Number (DNI/NIF) was not available, only the number and letter, nor the
names and surnames. Since corrective measures were adopted without
being required by the Spanish Data Protection Agency (AEPD), their severity and mitigation should be considered.
b. Regarding the imposed fine of €100,000 for the infringement of
Article 33 of the GDPR, should it be found to have occurred, the
amount is completely disproportionate given that
the breach was voluntarily reported by CECOTEC, there are no
user complaints, and the delay with respect to those 72
hours is only 3 days because the full
extent of the breach was not known, and there were also public holidays within the
required period, as was demonstrated.
c. Regarding the imposed fine of €40,000 for the infringement of Article 34 of the GDPR, it should be noted that, should this infringement be found to have occurred, the amount is completely disproportionate, given that there is only evidence of six actual data subjects, their data is not sensitive or of a special category, and identity theft would not currently be possible since the complete National Identity Document (DNI/NIF) number and letter are not available, nor are the full names and surnames.
- The corrective measures that were subsequently adopted and communicated to the Spanish Data Protection Agency (AEPD) must be considered, listing them and referencing the evidence of their adoption provided in the proceedings.
Finally, it is reported that the Company continues to improve, currently undergoing a GDPR compliance audit and updating its risk analyses, conducting Data Protection Impact Assessments (DPIAs), and verifying its security measures. And that it is willing to accept any
proposal for improvement.
TWELFTH: On April 30, 2024, CECOTEC was notified of the initiation of the
procedure agreement, in which—responding to the request made through FIRST ADDITIONAL CLAUSE of the submitted statement of allegations, as well as to the prior allegation
made—it was clarified that it is possible to submit supplementary allegations
until a Proposed Resolution is issued, and that the deadline for submitting
allegations to the initiation agreement will end once the granted period has elapsed, which was
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 19/173
subject to extension (the calculation of which has resumed upon notification on that same
date, April 30, 2024, of the copy of the file that was sent to its postal address).
As a result, CECOTEC submitted a second statement of objections to the initial agreement dated May 8, 2024 (hereinafter, Objection AI #2), in which, having had access to the file, it formulated, in summary, four additional objections to those already made:
FIRST. - LACK OF GRADING.
o It is stated on page 222 of the administrative file relating to ‘SIGNIFICANT EVIDENCE FOR THE SEVERITY OF THE SANCTION’ that the Inspector only considered CECOTEC's turnover figure for the 2022 fiscal year as a criterion for determining the severity of the sanction.
o Although the initial agreement briefly mentions the seriousness, nature, and duration of each of the infractions, in the opinion of the Spanish Data Protection Agency (AEPD), the Agency has not considered any criteria for determining the severity of the sanctions aimed at mitigating them, as already pointed out in its initial statement of allegations.
o Although the initial agreement briefly mentions the seriousness, nature, and duration of each of the infractions, the AEPD believes that the Agency has not considered any criteria for determining the severity of the sanctions aimed at mitigating them, as already indicated in its first written submission. It is added that: “In accordance with Guidelines 04/2022 of the European Data Protection Board on the calculation of fines, following the structure of the GDPR, after having assessed the nature, seriousness, and duration of the infringement, as well as its intentional or negligent nature, which,
is solely and exclusively what the Spanish Data Protection Agency (AEPD) has considered in this case, the supervisory authority must take into account the remaining aggravating and mitigating factors
listed in Article 83, paragraph 2, of the GDPR, as well as the categories of personal data affected. And yet, CECOTEC reiterates that the AEPD has not assessed the limited relevance of the categories of personal data
affected, nor the fact that there has been no prior infringement by CECOTEC, nor has it considered the degree of cooperation with the supervisory authority to mitigate risks.
Furthermore, they add that Article 76.2 of the Spanish Data Protection Act (LOPDGDD) states that Two circumstances that are not present in this case must be taken into consideration to mitigate or aggravate the sanction: c) The benefits obtained as a consequence of committing the infraction. f) The impact on the rights of minors. Therefore, since they are not present, they must be considered to mitigate the sanction.
SECOND. – REGARDING THE ATTACK BY A THIRD PARTY (HACKER) AND THE COMMUNICATION MAINTAINED BY THE INSPECTOR.
• It is emphasized that CECOTEC is the victim of a cyberattack,
and that no damages have been proven,
and that the presumption of innocence of CECOTEC remains intact.
• In relation to what is stated in FACT SIXTH (page 12) regarding the contact that the inspector recorded in his API Report concerning
28001 – Madrid 6 sedeagpd.gob.es 20/173
had maintained contact with the cyber attacker on August 4, 2023, in which
the user responded, confirming that the database belongs to the
company and contains 1,086,185 records, attaching a new
sample; CECOTEC states the following:
(i) Given that page 203 shows the email address of
a possible identifiable perpetrator,
it is reported that the corresponding complaint will be filed with the National Police, a copy of which
will be attached to the administrative file.
(ii) It also notes that there is no record that this AEPD (Spanish Data Protection Agency)
provided said information in any request, which
would have been useful and would not have prejudiced the investigation; and
that INCIBE (National Cybersecurity Institute) also failed to provide it, stating that it could not
determine if the information was truthful.
As in the first statement of allegations No document was attached to the aforementioned supplementary statement.
Subsequently, as previously announced, a new statement of allegations was submitted on May 13, 2024, to provide a copy of the complaint filed by CECOTEC with the National Police regarding cybercrime, which was referenced in its supplementary statement. This is attached as DOCUMENT 1.
THIRTEENTH: On June 3, 2024, the inspector issued an order to open the probationary period of the proceedings.
In this probationary order, in addition to considering the file reproduced, the inspector also issued and attached the two official notices issued by the investigating officer on the same date—regarding verification of the unavailability of access to the SOFTWARE.1 platform and attaching a copy of the database schema published by the developer for version 1.6 of the platform. ***SOFTWARE.1-, CECOTEC is required to provide the following documentation/information:
- In order to verify that, as CECOTEC states in its allegations,
the fields of the sample provided by the cyber-attacker to the inspector on
August 4, 2023, do not match those of the so-called "access" table
of the ***SOFTWARE.1 platform at the time of the cyber-
attack, the provision of said access table is required.
It is specified that the content of the aforementioned access table must be provided
with all the records reflected therein as of April 5,
2023; as well as the table subsequently obtained by the cybersecurity department
between April 12 and 14, 2023, in order to verify the
veracity of the cyberattack.
It is noted that said table should preferably be submitted in
electronic format, although it may be provided on a physical medium (CD or USB) if it cannot be converted into Electronic format, by
28001 – Madrid 6 sedeagpd.gob.es 21/173
exceeding the maximum size allowed in the Notific@ system.
- Having reviewed Annex 2 of the document dated August 30, 2023, entitled
“estructura.presta.png”, you are required to submit it again in a
suitable format and resolution to ensure that its data is
clearly legible.
You must expressly state whether the aforementioned Annex 2 corresponds to the
database structure of the platform customized by
CECOTEC on the date of the cyberattack (April 5, 2023), or on the
subsequent dates of verification of the cyberattack by CECOTEC.
And in any case, you are required to specify the dates on which this structure of Annex 2 was used by
CECOTEC as the platform's content management system.
- Please provide supporting documentation for the changes made to the
aforementioned database structure of the platform since April 5, 2023. from April
2023 to the present.
- Having denied that the number of records on the platform matches
that indicated by the cyber-attacker, supporting documentation is required
to prove the number of records contained on the
platform as of the date of the cyberattack (or verification by CECOTEC of the
same), distinguishing the following:
- On the one hand, a document proving the total number of holders of
personal data contained on the platform, broken down by
“consumers, suppliers, and manufacturers”.
- On the other hand, a document proving the total number of holders of
personal data corresponding to natural persons.
On 4/07/24, CECOTEC responded to this initial evidentiary agreement,
requesting a copy of the two Proceedings issued on June 3, 2024,
and clarification regarding the scope of the “supporting documentation for the changes
undergoed by the platform since the 5-4-23 to the present,” and providing 5
documents:
- Document No. 1 provides the “access” table, which is understood to have been
requested by the instructor, containing 2,047 accesses from 18 profiles.
- Document No. 2 corresponds to the generic structure of the ***SOFTWARE.1 database.
- Document No. 3 includes the customized structure that
CECOTEC used on the platform, and Document No. 4 includes
a brief explanation of its functionalities for better development and
monitoring of the entity's activity. It is noted that the
structure shown in Document 4 “was used by CECOTEC
from June 2016 until the platform's closure date.”
- Document No. 5 includes a screenshot showing
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 22/173
You can check the total number of personal data holders
contained on the platform as of the date of the cyberattack, leaked by
consumers, suppliers, and manufacturers. It should be noted that: “The number
shown is the total number of users, with the contact details corresponding to
individuals, although some of them refer to data of
individuals who are not acting in their personal capacity, but rather
representing a company or in the course of their
professional activity.”
FIFTEENTH: In view of the documentation provided by CECOTEC to date, and the requests made by the same, on August 27, 2024, the investigating officer issued
an additional order for further evidence.
This agreement to extend the evidentiary period aims to provide a copy of the
proceedings requested by the same, clarify the doubt raised, and require CECOTEC to provide the following documents:
- Provide the complete content of the table that appears in the custom structure
of ***SOFTWARE.1 submitted as Document 3, with the
name “***TABLE.1” (hereinafter, table ***TABLE.1), exactly as it
appeared on the date of the cyberattacker's announcement (April 5, 2023), or on the
date the checks were carried out by your
cybersecurity department (April 12 and 13, 2023). This is because the Access table
submitted as Document 1, regarding employee profile types of the
entity, does not correspond to the Access table requested by the
instructor.
Having indicated in your response to the evidentiary agreement that the
structure of document 3 was the one in effect on the date the platform closed (January 2021), you are required to clarify whether this structure
remained unchanged until April 5, 2023, the date of publication of the
alleged cyberattack. If it was different, please provide a screenshot of the
new structure.
On September 20 and 24, 2024, CECOTEC responded to the agreement for
extension of evidence (hereinafter, [ContEvidence#2]), providing an Excel file
encrypted with a password, which, according to the defendant, contains the aforementioned table
***TABLE.1 found on its platform, stating that: “According to the
information provided by the IT department, it should be noted that the content of
table “***TABLE.1” submitted herein is the same as it was on the date of the platform's closure in December 2022. In this regard, it is confirmed that this
content is the same as it was on the date of the cyberattacker's announcement (April 5, 2023) and on the
dates on which the checks were carried out (April 12 and 13, 2023).”
SIXTEENTH: On February 6, In 2025, the content of the second sample provided by the malicious actor, consisting of 1,000 records, was compared with the data contained in Table ***TABLE.1 provided by CECOTEC, in order to verify the matches and determine if the cyber-attacker had access to these records, as well as to ascertain how many people were affected, if any.
28001 – Madrid 6 sedeagpd.gob.es 23/173
As a result of these actions, a report dated February 14, 2025, was issued and attached to these proceedings. This report includes the Excel spreadsheet
of matches organized by National Identity Document (DNI), following DNI validation. The summary of the results obtained is also included:
1. Analysis of records and personal data from Table ***TABLE.1 of CECOTEC.
Note the Total number of records, fields, and personal data
contained therein.
2. Analysis of personal data and data subjects in SAMPLE 2 provided by the
malicious actor.
It is noted that the personal data contained in the sample of 1000
records corresponds to a total of 933 individuals who appear with a
valid ID number, 50 individuals whose ID number is invalid or incorrect, and
17 correspond to companies. The fields and personal data
contained in said sample are detailed.
3. Comparative analysis between sample 2 and table ***TABLE.1.
It is noted that: “Sample 2 contains 1000 records, all of which
are included in table ***TABLE.1. It is observed that they match
even the identifier codes that are automatically generated by the database
which the malicious actor could not deduce if they had not accessed
it. (id ***TABLE.1, id country, id costumer, id supplier...etc).
The 933 individuals with verified ID numbers are included
in table ***TABLE.1 of CECOTEC and include the data that has been
indicated.”
SEVENTEENTH: On March 7, 2025, CECOTEC was notified of the
Proposed resolution of the sanctioning proceedings of February 26, 2025, whereby
in light of the evidence presented, it was considered proven that the aforementioned table
“***TABLE.1” contained in the ***SOFTWARE.1 platform of CECOTEC had been
the target of the cyberattack published on the dark web on April 5, 2023, and that as a consequence
of this attack, it had been established that the malicious actor had accessed, at least, the
personal data contained therein corresponding to 933 individuals,
instead of the 6 individuals whose breach was detected and reported by the company.
And as a consequence, the response Regarding the allegations made against the initial agreement, it was agreed to increase the amount of two of the fines initially
set in the initial agreement related to the number of affected parties (Articles 5.1.f) and 34 of the GDPR). Consequently, the following administrative fines are proposed for the commission of the following infringements:
- For infringement of Article 5.1.f) of the GDPR, a fine of €300,000.
- For infringement of Article 32 of the GDPR, a fine of €750,000.
- For infringement of Article 33 of the GDPR, a fine of €100,000.
- For infringement of Article 34 of the GDPR, a fine of €100,000.
28001 – Madrid 6 sedeagpd.gob.es 24/173
A copy of the Proceedings is attached to this Proposal. issued on February 14, 2025, as it was the only document attached to the file that was not in the possession of the accused party.
EIGHTEENTH: On March 18, 2025, CECOTEC submitted a brief of arguments against the proposed resolution of the proceedings, without attaching any documentation, stating a total of six arguments (preliminary, and first through fifth), which are listed below and are addressed in Legal Basis V of this Resolution:
PRELIMINARY: The arguments and grounds already made in the previous briefs are reiterated.
FIRST: Disputed Facts. As an introduction to arguments
second through fourth, the three facts declared as disputed in the proposed resolution are mentioned.
SECOND: Regarding the number of records ultimately affected.
2.A. Principle of culpability and proportionality in relation to the infringements
contemplated in Articles 5.1.f) and 32 of the General Data Protection Regulation (GDPR). Lack of a causal link.
2.B) Lack of graduated sanctions.
THIRD. – Regarding the effectiveness of the technical and
organizational security measures in place at the Company.
3.A. Infringement of the principle of legality and lack of liability under Article 5.1 f) of the GDPR.
3.B. Infringement of Article 32 of the GDPR, lack of culpability, and lack of
proportionality.
FOURTH. – Disagreement with the starting date for notification of the
breach. Lack of proportionality of the infringement under Article 33 of the GDPR.
4.A) Starting date. It states that it is April 17, 2023, and that, subsidiarily,
it should be 14-4-24.
4.B) Lack of proportionality, infringement of Article 33 of the GDPR.
FIFTH.—Lack of need to notify the data subjects at the time of the breach. Infringement of Article 34 of the GDPR.
From the actions carried out in this procedure and the documentation contained in the file, the following have been established:
PROVEN FACTS
FIRST: It is established that on 5-4-23, the Spanish National Cybersecurity Institute (INCIBE) detected a post on a dark web forum
28001 – Madrid 6 sedeagpd.gob.es 25/173
in which the sale of a database of a Spanish company was advertised, whose data corresponded to that published about CECOTEC on infoempresa.com,
sending the same company an email on the same day, 5-4-23. 2:53 PM with
subject “cybersecurity incident alert”, the content of which was as follows:
“On April 5th, a post was detected on the sinister.ly forum where the
malicious actor operating under the alias “***USER.1” claims to possess
a database with approximately 1 million customer records from a
well-known Spanish company whose corporate name is not mentioned. However,
it specifies that it is a company founded in 1995, specializing in the sale of
household goods and appliances, with a net worth of €25,080,126,
whose annual revenue would reach €106,423,475 and whose profits amount to
€16,733,555.
It has been verified that the affected entity could be your company (CECOTEC
INNOVACIONES SL) given the match with the revenue and founding data
provided by the malicious actor. (https://www.infoempresa.com/es—
es/es/empresa/cecotec innovacións—sl)
To access the complete database, it is necessary to contact the malicious actor via email or instant messaging (Telegram or ICQ).
Additionally, ***USUARIO.1 provides a link to access a sample of the data for sale. The sample is an image showing a table with personal information of 17 individuals, some of them Spanish, who are presumed to be clients of the affected company. Although the information is masked in some columns of the table, the following data appears in plain text: - Postal address (city, country, and postal code) - Mobile phone number - National identity document number.
To date, no comments have been posted,
0 responses that would allow us to determine if the information is truthful and if it has been exposed in other leaks.
Sources: (…)
We are bringing this to your attention in case you are unaware of it or wish to verify whether
a leak has actually occurred and take appropriate measures.
In accordance with the GDPR, if the information is real and has affected the
confidentiality, availability, or integrity of personal data, the data controller
must assess whether there is a risk (…)”.
Through the source mentioned in said email, it was possible to access the aforementioned
advertisement for the sale of the database, which included a sample of 17 records from
the database, and contained the following, which has been reflected in the email
of April 14, 2023, submitted as Annex 7 of document Resp#1 from
CECOTEC:
“(…)
Message: I have a Spain E-commerce database.
It is a renowned Spanish company that was founded in 1995. The company
specializes in household articles and small electrical appliances.
It has a Net Worth of €25,080,126; Turnover of €106,423,475; Earnings of €17,733,555; Year-end results; and an average daily purchase value of US$749,795.
I have almost 1 million entries of customer, manufacturer, and supplier phone leads.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 26/173
Check the picture here: https….”
(Spanish translation by this Agency)
“(…)
Message: I have an e-commerce database in Spain.
It is a renowned Spanish company that was founded in 1995. The company specializes in household goods and small appliances.
It has a Net Worth of €25,080,126; Turnover of €106,423,475;
Earnings; Earnings €17,733,555. Year-end results, and average daily purchase value of US$749,795.
I have almost 1 million entries from customers, manufacturers, and suppliers with phone numbers.
Take a look at the image here: https....”
SECOND: On April 19, 2024, at 6:19 p.m., CECOTEC notified this Agency that a breach of personal data confidentiality had been detected, affecting six real individuals. They provided a report from their Data Protection Officer (DPO) which
indicates that the initial sample of 17 records contained in the malicious actor's advertisement matches the contents of a table called “***TABLE.1” from a former online store platform called
“***SOFTWARE.1,” which CECOTEC has been using to manage its customers since 2016. The (…) ***SERVICE.2 was closed in January 2021, but
remained active in ***INTERFACE.1. It is noted that it is not considered necessary to
notify these six affected individuals of the breach, as there is no probability
of which entails a high risk after the assessment carried out.
Regarding the processing of personal data carried out through the aforementioned
former online store platform, it is established that:
- CECOTEC began processing the personal data obtained from its
customers to manage the online store contained in the aforementioned open-source web services-based platform ***SOFTWARE.1 in 2013
(according to the submitted RAT).
- However, the company states that the ***SOFTWARE.1 platform did not
begin to be used until 2016, which is not reflected in the updated RAT
submitted to the proceedings. The company does not provide evidence of this.
Nevertheless, it has been verified that the personal data
contained in the table “***TABLE.1” all refer to data obtained
between 2016 and 2021, and this fact is therefore considered true in favor of the
company.
- In January 2021, the processing was modified in the terms stated
in the document from Response #1, which indicates that “the platform was replaced by a
new online store, internally replaced, which adopted more modern open-source web development technologies,
the transition of which was completed in
January 2021,” but: “despite the closure of the original platform,
limited access to it (***INTERFACE.1) has been maintained for the sole purpose of
28001 – Madrid 6 sedeagpd.gob.es 27/173
being able to address requests, needs, and/or complaints from the company's
customers.”
It is noted that as of the date of the breach (April 5, 2023), the platform corresponded to
version 1.6 of ***SOFTWARE.1, whose basic structure was customized by
CECOTEC, and is provided as Annex 2, and was outdated, unsupported, and
with direct internet access (using a username and password) to the aforementioned
INTERFACE.1 or ***SERVICE.1 (), indicating CECOTEC's Response #2 that:
“(…) The reason the platform was still accessible on the Internet on
that date is that the migration of integrations from the
old platform to the new one has not yet been completed. ***INTERFACE.1 remains active due to: “the need
to maintain active integrations with our new online store. These
integrations operate in read-only mode and are essential for the functioning of
our system, so updating the platform to a more recent version
could cause problems with them. Furthermore, some of these
integrations still require access to ***INTERFACE.1 of the
platform from the Internet. However, in the coming months, the necessary technical steps will be taken
to migrate all the platform's
integrations and completely eliminate the platform's
Internet exposure.”
- Finally, it has been established by means of a Proceeding dated June 3, 2024, that
CECOTEC has proceeded to disable internet access to the
platform referenced in the AlegAI#1 document of April 25, 2023. However,
no evidence has been provided to justify that they have ceased
all personal data processing operations carried out
through said platform, and it has not been established that the defendant has
either ceased processing, or blocked and/or deleted the
personal data contained therein.
THIRD: CECOTEC has acknowledged that, as a consequence of the cyberattack referred to in the preceding facts, a breach of confidentiality occurred in the database.
This breach affected the personal data contained in one of the tables of this platform, ***SOFTWARE.1, called “***TABLE.1,” the complete contents of which were provided by CECOTEC on September 24, 2024 (…).
It has been verified that the malicious actor was able to access some of the personal data contained therein without authorization and offered it for sale on a dark web forum on April 5, 2023.
A sample of 17 records was published, which correspond entirely to the contents of the aforementioned table. Of these, 6 correspond to individuals, and the rest are test data.
This is acknowledged by the respondent in the following documents:
- Attached to the breach notification of April 19, 2023, is a report from the
Data Protection Officer (DPO), which states that on the ***SOFTWARE.1 platform: “A variety of personal data essential for the operation and
management of the online store are stored; however, in the context of the potential incident reported
by INCIBE, the allegedly affected data relates to table ***TABLE.1
within the database.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 28/173
- In the first detailed incident report submitted as Annex 3 to your letter
dated August 30, 2023 (Resp#1), CECOTEC acknowledges that the 17 records in the sample contained in the advertisement match, but does not believe that
the statements made by “***USER.1” are viable or, if applicable, truthful.
- As Annex 7 to the first written response to the investigation request
(Resp#1), an email is attached that the Cybersecurity Director
of CECOTEC sent to the CECOTEC Data Protection Officer on April 14, 2023, in which,
after carrying out the relevant investigations to verify the
plausibility of the attack based on the initial sample of 17 records that the malicious actor
had published in their announcement, they state the following (emphasis added):
“After conducting the analysis, it was seen that the records in the table match those
of the old CECOTEC store (…) which was closed in 2021. However,
currently, some people use that page for reference. After
investigating together with the e-commerce and infrastructure department, we were able to see
that the records the attacker has in the database are from 2016 to
2020, assuming they have the 1,000,000 records they claim to have, Since
it only shows 18 records in the attached image. This table
contains user data such as addresses, postal code, city, phone number, and ID number.
- Subsequently, the first written statement of allegations submitted against the initial agreement (Alleg AI#1) acknowledges that the aforementioned CECOTEC platform “was the victim
of a cyberattack,” and therefore, that the origin of the breach was the illegitimate access
by the malicious actor who published the advertisement, making the following statements:
“It is important to emphasize that the security breach reported on April 19,
2023, occurred on the CECOTEC platform not due to a lack of security measures or their ineffectiveness, but due to an attack by a third party (hacker)
who gained unauthorized access to the system” (…)
“With regard to the CECOTEC platform, which, as has been proven, was
illegally accessed by a third party, we must emphasize, as has been
informed the Spanish Data Protection Agency (AEPD) during the preliminary investigations, that technical and organizational security measures were in place
to prevent access by
unauthorized third parties, such as having “access controls”.
or “It has not been proven that the security breach suffered by CECOTEC posed a “high risk” (…)” initially there were doubts about the certainty of
the breach, but it was finally reported to the Supervisory Authority
as information was obtained.”
- This is confirmed in the second statement of allegations submitted on May 8,
2024 (AlegAI#2). Upon receiving a copy of the file, it is stated: “(…) The
company has been the victim of a cyberattack on its systems, corrective measures were adopted
immediately, and adequate measures were in place prior to the
incident.”
- And finally, on May 13, 2024, a copy of the
complaint filed with the National Police is submitted, in which CECOTEC reports
having been the victim of an alleged crime due to the cyberattack announced at
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 29/173
dark web forum to which this file refers. Specifically, it is
indicated that:
: “II.— That, as a result of said transfer, CECOTEC has become
aware of the identifying information used by the individual who
allegedly obtained personal data of consumers and/or
users of the Company illicitly, and is subsequently selling it,
through the forum https://sinister.ld” (data copied from the advertisement published on April 5,
2023, by the cybercriminal).
“IV.— Considering that the third party, whose data is provided through this
Complaint, is engaged in the commercialization of a database of
personal data of consumers and/or users, allegedly of the Company,
and that other commercial companies unrelated to the
Company may be affected, this party wishes to make the information available to the State Security Forces and Corps. which is available for the appropriate legal purposes.
FOURTH: Regarding the scope of the personal data breach, it should be noted that evidence has been presented and it has been proven that the malicious actor gained unauthorized access to at least 1,000 records
contained in the aforementioned table “***TABLE.1” of CECOTEC, of which 933
corresponded to individuals with valid ID cards, whose personal data had not been encrypted or pseudonymized, but appeared visible and exposed in its entirety, without masking in any of its 24 fields. The following can be deduced from the
following evidence attached to the proceedings:
- On August 4, 2023, following the instructions contained in the
INCIBE alert emails included in the proceedings, the inspector
contacted the malicious user and obtained a second sample of 1000
records from the database. This is stated in the fourth conclusion of his
report as follows:
“4. The inspector contacted the user who claimed to be selling
the alleged database in order to verify the information and
confirm the existence of a personal data leak, (…) and it contains 1,086,185
records with customer data. The user provided the inspector (…), which are additional
to the 17 published in the sample, with an identical field and data structure to the
published screenshot. Regarding this field structure, the company had
confirmed that it corresponds to the table “***TABLE.1” in its database, which
contains the following personal data of 1,000 people: “***TABLE.12, postcode,
city, other, phone, mobile_phone, VAT_number, ID number.”
- As the API report indicates, on November 2, 2023, the following were incorporated into the proceedings:
A copy of the reply email sent by the malicious actor to the inspector on August 4, 2023, and the sample of 1,000 records obtained from it.
Specifically, the email contains the following literal content, which is translated below:
“Re: Spanish leak 1 million records From RKSinc©protonmail.ch
To paulecrypt
Date Friday, August 4, 2023 at 11:28 AM Many thanks for replying.
Yes, the company is CECOTEC.
I accept BTC and maybe USDT (ERC20, TRC20)
majorly.
As soon as your payment comes in, send your email ASAP.” --Price is
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid Seeagpd.gob.es 30/173
$3,000 (negotiable)
1,086,185 cecotec.es customer, manufacturers, suppliers phone data 05/01/2023
7:25 pm Text Document 166,117 KB J
837,606 cecotec.es Customers (mobile Phone sorted) data 05/11/2023 7:54 pm
CSV File 128,060 KB *
* The first file is 1M Plus, when I sorted the phone numbers to (Mobile and
customers only) it came down to 837k plus.
You can see the files there.”
(Spanish translation by this Agency)
“Yes, the company is CECOTEC. | Accept BTC and maybe USDT (ERC20, TRC20)
mainly. As soon as your payment arrives, please send your… as soon as possible.
--Price is $3,000 (negotiable)
1,086,185 cecotec.es customer, manufacturers, suppliers phone numbers
01/05/2023 7:25 pm Text document 166,117 KB J
837,606 cecotec.es Customer data (sorted by mobile phone)
11/05/2023 7:54 pm CSV file 128,060 KB *
* The first file is 1M Plus, when I sorted the phone numbers to (Mobile
and customers only) it was reduced to 837k plus.
You can see the files there.”
- In the first written response to the trial agreement of July 4, 2024, CECOTEC
submits as document 3 its customized platform structure where
it can be observed that there is a table called “***TABLE.1”, whose fields match
those of the sample of 1000 records that the inspector obtained from the
cybercriminal. CECOTEC indicates that this structure was in effect when the platform was shut down
in January 2021, remaining unchanged at the time of the
cyberattack.
- In the second written response to the evidence dated September 20, 2024, CECOTEC submitted
as DOC 1 an undated and unsigned Excel document, stating that it
corresponds to the complete content of the aforementioned table “***TABLE.1” which was
required during the testing phase, and noting that: “According to the
information provided by the IT department, it should be noted that the content of the
table “***TABLE.1” submitted in this document is the same as it was on the platform's closing date
in December 2022. In this regard, it is confirmed that this content
is the same as it was on the date of the cybercriminal's announcement (April 5, 2023) and on the dates
when the checks were carried out (April 12 and April 13, 2023).”
- On February 14, 2025, the investigating officer issued a statement of the
procedure for recording the data obtained from the comparison between the
records contained in the sample provided by the cyber attacker on August 4, 2023, and those contained in table “***TABLE.1” provided by
CECOTEC. Specifically, the following was observed:
“The Excel list of matches obtained by comparing
both lists, organized by National Identity Document (DNI), after performing DNI validation, is attached as Annex I. The summary of the results obtained is as follows:
1. Analysis of records and personal data from TABLE ***TABLE.1 OF CECOTEC.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 31/173
Table ***TABLE.1 provided by CECOTEC contains a total of 2,057,313 records
(rows), which are reduced to 2,054,164 records that have a mobile phone number. Therefore,
these do not match the total number of records that the malicious actor claims to have, which is 1,086,185,
of which 837,606 have a mobile phone number.
Table ***TABLE.1 contains 25 fields, which contain the following types of personal data:
i. Postal address 1 (indicating street, number, postal code, and city).
ii. Postal address 2 (only data that appears to be a continuation or complement of address 1).
iii. Complete identification codes: address code, country code, customer code.
iv. Supplier and manufacturer identification codes: these appear as 1 or 0.
v. First and last name.
vi. National Identity Document (DNI) number.
vii. Tax Identification Number (NIF) (always blank).
viii. Landline telephone number (not always completed).
ix. Mobile telephone number (completed in almost all cases).
*Fields that appear blank (NIF) or with a zero value are not mentioned, nor are those that do not contain personal data of individuals, such as alias, company, date, active, deleted, etc.
It should also be noted that not all records have all fields completed.
* 2. Analysis of Personal Data and Data Subjects in SAMPLE 2 Provided by the Malicious Actor
The personal data contained in the sample of 1000 records corresponds to a
total of 933 individuals with a valid National Identity Document (DNI), 50 individuals whose
DNI number is invalid or incorrect, and 17 companies.
The data is fully visible, without encryption or
pseudonymization.
The fields in Sample 2, containing personal data of individuals
with valid DNIs, total 933 people and are as follows*:
o Postal address 1 (indicating street, number, postal code, and city).
o Identifier codes: address code, country code, customer code,
supplier code, and manufacturer code.
o First and last name
o DNI number.
o Landline and mobile phone numbers.
*Fields that appear blank or with a zero value, such as alias, NIF, address 2, alias, etc., are not mentioned. And not all records have all fields completed:
3. Comparative analysis between sample 2 and table ***TABLE.1.
Sample 2 contains 1000 records, all of which are included in table ***TABLE.1. It can be observed that even the identifier codes automatically generated by the database match, which the malicious actor could not deduce without having accessed it. (id ***TABLE.1, id country, id customer, id supplier, etc.).
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 32/173
The 933 individuals with verified ID cards whose personal data
appear on the list are included in table ***TABLE.1 of CECOTEC, and
include the fields and personal data that have been indicated.”
- In the arguments presented on March 18, 2025, against the proposed
resolution, after receiving a copy of the aforementioned data verification procedure,
CECOTEC acknowledges that the breach affected a total of 933 individuals,
and requests that the penalty be determined taking into account this scope, and not the
1,086,185 that the cyber attacker claimed to have. Specifically, it states that:
or Page 2: “In addition to the above, after the verification carried out by the Agency between the
database provided by the attacker and the database provided by
CECOTEC, it is clear that: (…) The number of records that coincide
in both tables is nine hundred and ninety-three records (993).
p. 4: “Therefore, in accordance with the above: • It has not been possible
to prove that the attacker accessed 1,086,185 records, but only
993, making the amounts of the fines
imposed under Article 5(f) and Article 32 of the GDPR disproportionate (...)”.
p. 14: “However, it should be emphasized that, as stated in the
second allegation, the Agency itself acknowledges that the total number of
affected parties is 993, not one thousand, nor one million”.
p. 15: “Therefore: • The scope of the incident is 993 affected parties, not
1,086,185 as the attacker indicated”.
FIFTH: Regarding the notification of the breach to this Agency, the following chronology has been established:
1. CECOTEC received in its general inbox (…) the first email alerting the INCIBE cybersecurity incident on April 5, 2023, at 2:53 p.m., as referred to in the first proven fact. However, this alert email was not forwarded to those responsible for detecting and reporting the breach within the company, thus failing to comply with the provisions of the Security Incident Management Protocol approved by the company in April 2021, which stated that:
“Any employee of the organization who becomes aware of any indication of a security event or incident related to the protection of personal data, through any of the means indicated in point 2.1 of this document (regarding the sources of identifying a security breach), must report it within a maximum of 24 hours to the Data Protection Officer and their supervisor.” immediate supervisor and departmental superior”
This is acknowledged by CECOTEC in CECOTEC's Response #1 document: “On
April 5th at 2:53 PM, we received an email from INCIBE (Spanish Cybersecurity Institute) to our generic email address ***EMAIL.1 informing us
of a possible cybersecurity incident with the reference code
[INCIBE—CERT 113713032]. This notification was not addressed in a timely manner by this
entity, as emails received in this mailbox (which is intended for
28001 – Madrid 6 sedeagpd.gob.es 33/173
clients) are addressed in order of age. Furthermore, that week there were other
emails to address, considering that April 7th and 10th
were holidays.”
In the same document, Response #1 from CECOTEC, it is noted that the Data Protection Officer (DPO) became aware of this internal communication error and took action: “Finally, the Spanish Data Protection Agency (AEPD) is informed that on April 19, 2023, at 1:29 p.m., the Data Protection Officer sent an email to part of the team in Department 820 at CECOTEC, which manages the generic mailbox ***EMAIL.1, advising them of the importance of forwarding emails received in this mailbox related to data protection as soon as possible for proper handling.” This is evidenced by the aforementioned email of April 19, 2023, attached as Annex 7 to Response #1.
2. On April 12, 2023, at 11:10 a.m., a second alert email was received in the same inbox from INCIBE. This email followed up on and indicated that a response was still pending to the alert email sent seven days earlier, and included the alert number.
3. Upon receiving this second alert, the cybersecurity department sent an email to INCIBE on April 12, 2023, at 12:17 p.m., requesting the relevant information, which had been in CECOTEC's general inbox since April 5, 2023.
* ... 4. INCIBE responded to the cybersecurity department on April 13, 2023, at 11:12 a.m., sending the requested information, which corresponds to the content of the initial alert email of April 5, 2023. The verification process was then initiated by the CECOTEC cybersecurity manager, as acknowledged in the initial DPO report attached to the breach notification (emphasis added).
“On April 13 at 11:12 a.m., we received a reply from INCIBE indicating that a post had been detected on the "synister.ly" forum by a malicious actor with the alias ***USER.1, claiming to be in possession of (...)
As soon as this information was received, the CECOTEC cybersecurity manager, along with the IT department, began managing this alleged security breach by carrying out the necessary technical work and verifications.” to try to corroborate as soon as possible that the information provided by INCIBE does indeed affect CECOTEC.
5. On the same day, April 13, 2023, at 5:26 p.m., the cybersecurity manager concluded the investigation and informed INCIBE of the following:
“The data shown in the image provided by user ***USER.1 on ***FORUM.1 is test data. Furthermore, the website containing this data was shut down in 2021 and is no longer operational.
For now, we cannot determine whether it constitutes a data breach based solely on the image shown. The reference being discussed is
[***REFERENCE.1]. In any case, we are at your disposal for anything you may need.”
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 34/173
6. On April 14, 2023, at 2:31 p.m., an email from the cybersecurity department to the Data Protection Officer (DPO) of CECOTEC was submitted as Annex 7 (p. 110 of the file).
The email informed them of the incident, the responses to INCIBE, and the results of the investigation.
The text of this email is as follows:
(emphasis added)
Good morning,
On Wednesday, April 12, 2023, at 11:10 a.m., INCIBE-CERT notified us
(***EMAIL.2) via email at ***EMAIL.1 of the following:
(COPY EMAIL)
In this email, they did not provide any further information,
only a reference code to inquire about. However,
the subject line was descriptive, as it indicated the following: [***REFERENCE.1]
Possible cybersecurity incident.
Subsequently, the cybersecurity department sent an email that same Wednesday, April 12th, at 12:17 PM to the sender, incibe-cert (incidencias©incibe-cert.es), to determine which data indicated the potential security breach.
The email drafted by the cybersecurity department is as follows:
(COPY EMAIL)
Based on this, the cybersecurity department verified, through the links attached to the email, that the user ***USER.1 was indeed selling the alleged data on a private forum called ***FORUM.1.
However, the user never mentioned the organization Cecotec, only describing the activity of the supposed company to which the data belonged.
(COPY IMAGE OF THE FORUM ADVERTISEMENT).
On the other hand, the other attached link contains a screenshot
of the database with some data that the attacker was providing
to my preview of what the database contained.
(COPY THE IMAGE OF THE SAMPLE OF 17 RECORDS).
After performing the analysis, it was seen that the records in the table match those of
the old Cecotec store (…) that closed in 2021. However,
currently, some people use that page for reference.
After investigating with the e-commerce and infrastructure department, we were able to
see that the records the attacker has in the database are from 2016 to
2020, assuming he has the 1,000,000 records he claims to have, since
he only shows 18 records in the attached image. In that table
we found user data such as addresses, postal code, city,
user, phone number, and ID number.
We also tried to view the logs to trace the attack and identify the attacker,
but we couldn't get anything clear. We reviewed the Presta8hop logs
(the CMS is running on the old store) and they weren't very useful since they only
showed user logins. Furthermore, some logs recorded by the CMS were disabled at the time due to
performance issues and were not
reactivated later. We also saw that the
SOFTWARE.1 had several version vulnerabilities, so we can't
determine if that was the entry point. On the other hand, we couldn't see much at the
server level or regarding database access since it wasn't being
monitored.
After analyzing all environments, the cybersecurity department cannot
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 35/173
determine whether it was due to malware on a workstation or from the
web application itself, since at the workstation level we do not currently have
any system for monitoring equipment, and we also do not
monitor said web application.
However, we still do not know for certain what data the attacker has, and that is
why we wrote to INCIBE-CERT that same Thursday, April 13,
2023, at 5:26 PM from the cybersecurity department with the following:
(COPY OF LAST EMAIL SENT TO INCIBE).
We have not yet received a response to that email.
7. On April 17, 2023, the cybersecurity department confirmed with INCIBE that there had been no phishing attempt.
8. Finally, the resulting confidentiality breach was reported to this Agency on April 19, 2023, at 6:19 p.m.
This timeline is supported by the following emails, attached as Annexes 6 and 7 to Response #1 of the request (Page 98 of the file):
• Email dated April 12, 2023, at 11:10 a.m., sent by INCIBE to ***EMAIL.1, following up on the potential incident.
• Email dated April 12, 2023, at 12:17 p.m., sent by INCIBE to INCIBE, requesting more information about the potential incident.
• Email dated April 13, 2023 at 11:12 AM sent
from INCIBE to ***EMAIL.3 providing information about the possible
incident.
or Email dated April 13, 2023 at 5:26 PM sent
from ***EMAIL.3 to INCIBE.
or Email dated April 14, 2023 (Page 110 of the report), sent from
***EMAIL.3 to dpd@cecotec.es, in which the cybersecurity director informs
the Data Protection Officer (DPO) of the investigations carried out.
or Email dated April 17, 2023 at 11:48 AM sent
from ***EMAIL.3 to INCIBE requesting, for security reasons,
identity verification from INCIBE, as no response has been received from
INCIBE to the last email sent by ***EMAIL.3.
or Email dated April 17, 2023, at 12:38 PM, sent
from INCIBE to ***EMAIL.3, confirming the sender's identity.
INCIBE.
Or, an email dated April 19, 2023, at 1:29 PM, sent by
***EMAIL.3 to INCIBE, requesting that INCIBE update its email address for receiving future notifications to avoid potential
delays in responding.
Or, an email dated April 19, 2023, at 3:56 PM, sent by
INCIBE to ***EMAIL.3, responding to the request made by
CECOTEC.
SIXTH: The respondent acknowledges that the breach has not been communicated to
those affected whose data appeared in the samples.
28001 – Madrid 6 sedeagpd.gob.es 36/173
provided by the malicious actor, because the respondent considers that there is no
high risk of infringement of their rights and freedoms.
Thus, it is stated in the DPD reports submitted along with the initial notification
of the breach on April 19, 2023, and Response #1 to the request, that the respondent detected that
the breach had affected 6 real people whose personal data was
included in the first sample of 17 records published in the malicious actor's advertisement.
Furthermore, in its arguments to the initial agreement, it insists that it is not
necessary to notify the affected parties of the breach. And in its arguments to the
proposed resolution, even after having acknowledged that the breach affected 933
people, it continues to maintain that there is no obligation to notify the breach for the
reasons indicated in its arguments to the initial agreement.
SEVENTH: Despite the fact that multiple vulnerabilities and
deficiencies in the platform that could have been identified to have enabled the cyberattack that occurred
to which reference will be made in the following proven fact, it has not been possible
to determine with certainty what the entry vector of the cyberattack was, as
stated in the first conclusion of the API report, based on what
the cybersecurity manager of CECOTEC stated in the email
of April 14, 2023, which is included as Annex 7 of document Resp#1,
in which it is stated that: “We also saw that said ***SOFTWARE.1 presented several
version vulnerabilities, but we cannot determine if that is the entry vector,” and
“After analyzing all the environments, the cybersecurity department cannot determine whether it was
the fault of malware on a workstation or from the web application itself, since currently
we do not have any system for monitoring equipment from the workstation, in addition to not
monitoring the web application.”
However, it is established that the personal data obtained by The
cyber attacker's data had not been encrypted or pseudonymized, as the personal data contained in the sample of 17
records published in the advertisement (whose first and last names were
masked, while the rest of the data was published) appeared
visible and intelligible, as did the data in the sample of 1,000 records provided to the inspector, in which no personal data was
masked, leaving all the personal data
contained exposed.
EIGHTH. Regarding the vulnerabilities and deficiencies of the Platform
***SOFTWARE.1 detected and the preventive measures adopted by CECOTEC
as of the date of the cyberattack.
Specifically, regarding the organizational and technical measures that were
in place as of the date of the cyberattack and before the personal data breach was detected
to guarantee the security of the personal data contained in the former
CECOTEC online store platform ***SOFTWARE.1 (referred to as
preventive measures in the API report), the following has been established:
1. As of the date of the breach, vulnerabilities existed in the platform
28001 – Madrid 6 sedeagpd.gob.es 37/173
***SOFTWARE.1 used by CECOTEC, which affected ***SERVICE.1 and
***SERVICE.2, and that the platform was outdated and unsupported
since 2019 and had internet access (with a username and password).
The existence of vulnerabilities in the platform had been reported by the
cybersecurity manager himself in the email of April 14, 2023, in which
it was noted that: “We also saw that said ***SOFTWARE.1 presented
several version vulnerabilities, but we cannot determine if that was the
entry vector.”
The following is recorded in the report issued by the inspector on November 2, 2023, after accessing the platform on that date through the URL provided in the screenshots of previous emails (exchanged with INCIBE), which corresponded to the access address of the old platform based on SOFTWARE.1 (and the possible origin of the attack):
- This platform, despite being old and undergoing migration, remained active, providing direct internet access only to the SERVICE.1 section (they claim this was necessary for integration requirements with the new platform).
On the other hand, it has also been established that the old
platform used version 1.6.1 of ***SOFTWARE.1, which has been
confirmed to be an outdated version, unsupported since 2019, and with multiple critical vulnerabilities that
affected both ***SERVICE.2 (…) and ***SERVICE.1 (…).
Screenshots are also attached showing that prior to the
cyberattack, warnings were published about an SQL injection vulnerability
detected in version 1.6 of the platform that was being exploited by
attackers on servers hosting web services, and that an
update was released on July 26, 2022, to patch it. This is evident from the
attached screenshots, which show the following:
(i) A vulnerability notice for the ***SOFTWARE.1 platform, published on
July 26, 2022, on the INCIBE website, stating that “***SOFTWARE.1 has
released a security update that corrects a critical vulnerability,
therefore, it is recommended to update to the latest available version as soon as possible,” which specifically affects version 1.6, used by CECOTEC.
(i) A vulnerability notice for the ***SOFTWARE.1 platform, published on
July 26, 2022, on the INCIBE website, stating that “***SOFTWARE.1 has
released a security update that corrects a critical vulnerability,
therefore, it is recommended to update to the latest available version as soon as possible,” which specifically affects version 1.6, used by CECOTEC. (ii) Publication on the cybersecurity newsletter page
“Hispasec One a Day”, where this same warning appears regarding: “Attackers
actively exploit RCE vulnerability in the CMS ***SOFTWARE.1 of
July 28, 2022. Cybercriminals find a way to use a
SQL injection vulnerability to execute remote code on
servers containing web services of ***SOFTWARE.1”
2. Lack of adequate measures to guarantee platform traceability:
o This is evidenced by the statements made by the cybersecurity manager
of CECOTEC in the aforementioned email from
28001 – Madrid 6 sedeagpd.gob.es 38/173
April 14, 2023, when he states that:
“We also tried to view the logs to see the traceability and uncover the
attacker, but we couldn't get anything clear. Since we saw the logs of the
Presta8hop (CMS built on the old store) and weren't very useful since
they only showed user logins, and also, due to
performance issues, some logs recorded by the CMS were disabled and
were never reactivated. We also saw that said
***SOFTWARE.1 had several version vulnerabilities, so we can't
determine if that's the entry vector. On the other hand, at the server
and database access level, we couldn't see much since it wasn't being
monitored. After analyzing all the environments, the
cybersecurity department can't determine if it was due to malware on a
workstation or from the web application itself, since at the workstation level we don't
currently have any system for monitoring equipment, and
the web application isn't being monitored.”
Furthermore, CECOTEC's Response #1 acknowledges that the platform did not have appropriate security measures in place regarding user access control, stating that:
“(...)”
3. Regarding the lack of an updated risk analysis for the platform.
In this regard, as stated in API Report point 8: “it has been
established that a documented analysis was carried out on April 10, 2022. The company confirms that there are no risk analyses dated
prior to the aforementioned date; however, it has been established that the
processing activity affected by the breach began in 2013
(Customer Management).
This is established because in the document from Response #1, CECOTEC provides a Risk Analysis dated
April 10, 2022, and in Response #2 confirms that they did not carry out any previously,
they indicate that the platform had been operational since 2013, and they provide two
unsigned updates from 2022 and 2023, and it is acknowledged that the
company is currently undergoing a process of document review and deciding on
measures to be taken: “The Spanish Data Protection Agency (AEPD) is informed that, in the last year, the position of Data Protection Officer
has been held by three different people, There is no continuity in the functions of the Data Protection Officer as specified in Article 39 of Regulation 2016/679 of 27 April 2016 (hereinafter, “GDPR”). Therefore, the company is currently undergoing an urgent review of documents and is deciding on measures to be taken and procedures to be implemented, including a review of all risk analyses carried out and an assessment of the need to perform an impact assessment of these analyses.
4. Lack of approval and application of a Security Breach Management Protocol that complies with regulations.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 39/173
It is noted that the company had approved a Security Incident Management Protocol, which does not contain a signature, dated 22 April 2021, submitted with document Resp#1. No justification is provided that it was
communicated to company personnel prior to the breach.
It does not include the contact information of the individuals to whom cybersecurity incident alerts should have been communicated and those responsible for
detecting and reporting the breach.
- When asked to provide the “2022 update” cited by the respondent,
the respondent submitted, in Response #2, a Security Breach Management Protocol,
which is unsigned and dated July 31, 2023, after the
breach occurred and was detected (“Last updated: August 29, 2023”). This protocol is considered to have been adopted as a corrective measure
but did not exist as a preventive measure at the time the
confidentiality breach referred to in this case occurred, as
confirmed by the facts and the statements contained in this
same Response #2.
Furthermore, the API report states that, according to the documentation
provided by the defendant, the following preventative measures were in place
and implemented by CECOTEC before detecting the breach caused by the
cyberattack:
(…)
NINTH. Regarding the corrective measures adopted on the platform after the
breach occurred.
In view of the supporting documentation provided and the evidence presented, it is
considered proven that the company has adopted corrective measures on the platform following the breach:
- Those alleged in the written responses during the investigation phase, the
verification of which was confirmed by the inspector, who stated the following in the conclusion
of his report:
“After detecting the security breach, the following
reactive measures were adopted to strengthen the platform's security:
(…)”
- After learning of the initiation of preliminary investigative actions,
the company approved a Security Breach Protocol on July 31,
2023, updated on August 29, 2023, which it submitted along with its Response #2.
- After the agreement to initiate this case on April 1, 2024,
access to the platform from the internet was disabled.
In its document AlegAI#1, the respondent states that it disabled access to
the ***SOFTWARE.1 platform from the internet, which has been
verified by this investigating officer through a report dated June 3, 2024, by
28001 – Madrid 6 sedeagpd.gob.es 40/173
therefore, this corrective measure by CECOTEC is considered proven
after the initiation of the sanctioning procedure.
- It is also established that the platform remained accessible via the internet
until at least November 2, 2023, the date on which the inspector issued
a report stating that: “Access to the URL ***URL.1 remains
available, allowing access to ***SERVICE.1 of the software installation
***SOFTWARE.1”. Having acknowledged in its Response #2 that:
“The reason the platform is still accessible online is due to the need to maintain active integrations with our new online store. These integrations operate in read-only mode and are essential for the functioning of our system. Updating the platform to a newer version could cause problems. Furthermore, some of these integrations still require access to the platform's interface (INTERFACE 1) via the internet.”
Notwithstanding the foregoing, in the coming months the necessary technical steps will be taken
to migrate all platform integrations and
completely eliminate the platform's exposure to the Internet.
LEGAL BASIS
I
Jurisdiction and Procedure
In accordance with the powers granted to each supervisory authority by Article 58.2 of Regulation (EU) 2016/679 (General Data Protection Regulation, hereinafter GDPR)
and as established in Articles 47, 48.1, 64.2 and 68.1 of Organic Law 3/2018, of December 5, on the Protection of Personal Data and Guarantee of Digital Rights (hereinafter LOPDGDD), the Presidency of the Spanish Data Protection Agency is competent to resolve this procedure.
... Likewise, Article 63.2 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) establishes that: "The procedures
processed by the Spanish Data Protection Agency shall be governed by the provisions of Regulation (EU) 2016/679, by this Organic Law, by the implementing regulations issued thereunder, and, insofar as they do not contradict them,
subsidiarily, by the general rules on administrative procedures."
II.
Preliminary Issues
2.1. Regarding personal data, operations, and the data controller.
The GDPR aims to guarantee the right to data protection for natural persons, specifying in Article 4 what it considers "personal data," "processing operations" subject to the GDPR, and who is the "controller" of a processing activity, as follows:
- Article 4.1 of the GDPR defines "personal data" as "any information relating to an identified or identifiable natural person ("data subject");
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 41/173
an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier,
such as a name, an identification number, location data, an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person;".
- Article 4.2 of the GDPR defines “processing” as “any operation or set of operations performed on personal data or sets of personal data, whether or not by automated means, such as collection, recording, organization, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.”
- Article 4.7 of the GDPR defines a data controller as “the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.”
In the case under examination, during the investigation it was established that
CECOTEC acted as the data controller for the personal data
contained on a former online store platform called “***SOFTWARE.1”
whose ***SERVICE.2 was closed in January 2021, but remained partially
active in its ***SERVICE.1, where various types of personal data were processed
as defined in Article 4.1 of the GDPR.
Therefore, as stated in the established facts, it is proven that:
- On April 5, 2023, a cybersecurity incident occurred which
was reported by INCIBE to CECOTEC, warning them that on that day
an advertisement had been published on a dark web forum that this organization
monitors by the malicious user known as “***USER.1” in which
a database of almost one million records from a
well-known appliance company was offered for sale, the data of which could match
CECOTEC. All of this is detailed in the First Established Fact
of this proposal.
- Although the attack vector is unknown, it has been established
that the cyber attacker was able to access the personal data
contained in the online store platform “***SOFTWARE.1”, and in a
table called: “***TABLE.1: Customer and Order Addresses”,
according to CECOTEC's statement and as verified during the
investigation. The controversial issue of the number
of records accessed by the cyber attacker will be addressed later.
- This table “***TABLE.1” stored personal data of
CECOTEC customers generated between 2016 and 2020. To specify
the personal data that was processed, it is necessary to analyze the
information included in the table “***TABLE.1: Customer and Order Addresses”. For these purposes, the following information is included in the file:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 42/173
(i) On the one hand, two samples of the database
provided by the malicious actor are available:
The first sample (hereinafter, Sample 1) is the one that appeared in
the advertisement published on April 5, 2023 (of 17 records) on the
dark web, in which the malicious actor stated that they had a
database of almost 1 million records belonging to a
company whose data matched that published by
“infoempresa” of CECOTEC. This sample was the one
verified by CECOTEC upon receiving the INCIBE alert, noting in
its breach notification that the 17 records were located in
table ***TABLE.1 of this old online store platform.
Secondly, during the preliminary investigation phase, the inspector contacted the malicious actor to obtain a larger sample. The actor confirmed that the database belonged to CECOTEC (“Yes, it is CECOTEC”) and provided a larger sample of 1,000 records (hereinafter, Sample 2) on August 4, 2023. CECOTEC was able to verify its contents by providing them with a copy of the initiation agreement.
The two samples provided by the malicious actor contain the same 24 fields, arranged in the same order as in Table ***TABLE.1, which was subsequently provided by CECOTEC.
The structure of both samples is as follows:
“***TABLE.1,id_country,id_state,id_customer,id_manufacturer,id_supplier,id_warehouse,alias,company,lastname,firstname,***TABLE.11,*
**TABLE.12,postcode,city,other,phone,phone_mobile,vat_number,dn
i,date_add, active, deleted.”
(Translated into Spanish by this Agency)
““
(…),id_country,id_state,id_customer,id_manufacturer,id_supplier,id_warehouse,alias,company,lastname,firstname,address1,address2,
postalcode,city,other,phone,phone_mobile,vat_number,dn
date_add, active, deleted.”
(i) During the trial phase, the defendant was asked to provide, and did provide, the complete content of Table ***TABLE.1 from the former CECOTEC SOFTWARE.1 platform, which was the target of the cyberattack, dated September 24, 2024 (hereinafter, the table/Table ***TABLE.1).
This corresponds to an Excel document that the defendant claims to have extracted from the platform in question, stating that its content has remained unchanged since the platform's closure in January 2021 until the date of the cyberattack on April 5, 2023, although she provides no evidence to support this claim.
According to CECOTEC, the table contains data corresponding to the years 2016 and 2021. They refer to customer addresses and
orders, which include data on individuals and some data
corresponding to companies. This also matches the two
samples provided by the malicious actor.
The structure of this table is composed of the same 24
fields contained in the malicious actor's samples, to which
one more field, called “date_upd”, is added.
***TABLE.1,id_country,id_state,id_customer,id_manufacturer,id_supplier,id_warehouse,alias,company,lastname,firstname,***TABLE.11,*
**TABLE.12,postcode,city,other,phone,phone_mobile,vat_number,dn
i,date_add,date_upd, active,deleted.”
(Translated into Spanish by this Agency)
“
(…),id_country,id_state,id_customer,id_manufacturer,id_supplier,id_warehouse,alias,company,lastname,firstname,address1,address2,
postalcode,city,other,phone,phone_mobile,vat_number,dn
date_add, date_upd, active,deleted.”
In conclusion, it follows that the data structure contained in the
two samples provided by the malicious actor and the table “***TABLE.1” contained
in the old ***SOFTWARE.1 1.6 platform customized by CECOTEC has
24 matching fields, the only difference being the inclusion of an additional field
in the Excel document provided by CECOTEC, extracted from the table
***TABLE.1, which refers to “date_upd”, corresponding to the updated date.
This field is automatically generated with each update of the
platform. Therefore, given that this lack of matching was alleged in the
arguments to the proposed resolution, it should be noted that the lack of matching of
this field does not preclude the cyberattacker from having the
personal data that appears in the other fields included in the sample, which do
match the table.
Furthermore, according to the Proceedings issued on February 6, In 2025, when comparing the data from sample 2 of 1000 records with those included in table 1 of CECOTEC, it was found that:
“Table 1 contains a total of 2,057,313 records, in whose fields the following types of personal data are contained:
a. Postal address 1 (indicating the street, number, postal code, and city).
b. Postal address 2 (only data that appears to be a continuation or complement of address 1).
c. Complete identifier codes: address code, country code, customer code.
d. Supplier and manufacturer identifier codes: these appear as 1 or 0.
28001 – Madrid 6 sedeagpd.gob.es 44/173
e. First and last name.
f. National Identity Document (DNI) number.
g. Tax Identification Number (NIF) (always appears blank).
h. Landline phone number (not always completed)
Mobile phone number (completed in almost all cases).
*Fields that appear blank (NIF) or with a value of zero, or those that do not contain personal data of individuals such as alias, company, date, active, deleted, etc., are not mentioned.
It is also noted that not all records have all fields completed.
Therefore, it is established that within the aforementioned table “***TABLE.1,” which was the target of the cyberattack, CECOTEC stored and processed various types of personal data
corresponding to natural persons, the processing of which must be governed by the provisions of the GDPR.
Secondly, there is no doubt that, as of the date of the cyberattack and currently, CECOTEC continues to process the personal data contained in said former online store platform, regarding which it acknowledges the following:
- This platform was created in 2013 “as an online store designed using the software ***SOFTWARE.1, dedicated to the creation and management of virtual stores for e-commerce”; and “was replaced
by a new, internally developed online store that adopted more modern open-source web development technologies (…) This transition was completed in early 2013.” 2021.
- However, despite being closed in its (…), the company acknowledges that
it continued to use the old platform in its (…) to perform certain
data processing operations, as follows: “Despite
the closure of the original platform, limited access to it (its ***INTERFACE.1) has been maintained for the sole purpose of addressing requests,
needs, and/or complaints from the company's clients.” Thus,
the defendant states that: “as of the date of the breach, therefore, the
***INTERFACE.2 (…) of this platform was not operational,
only ***INTERFACE.1 ((…) ***SERVICE.1) remained active,
which allows adding/editing/deleting products and managing customer data.”
Therefore, it is an acknowledged fact that, as of the date of the cyberattack (April 5, 2023), the
company continued to perform several of the personal data processing operations
contained on this old platform referred to in Article 4.2
of the GDPR, given that it continued to store more than 2 million records in this
table “***TABLE.1”, and accessed it to perform query,
extraction, and use operations on the personal data that were necessary to resolve
these incidents.
With regard to the responsibility for the processing, since the company
determined that the old platform would continue to be used in (…) “***SERVICE.1”, in
28001 – Madrid 6 sedeagpd.gob.es 45/173
parallel to the new platform, it is considered that it continued to be the
controller of the processing, because it continued to establish the purposes and means related
to the processing of the personal data that continued to be stored in
it. Therefore, CECOTEC's status as the
controller of this data, pursuant to Article 4.7 of the GDPR, is not a matter of dispute, which This, in turn, makes CECOTEC responsible for the infringements arising from its failure to comply with its obligations as the data controller.
In other words, it has been established that on the date of the cyberattack (April 5, 2023), the
former CECOTEC online store platform contained a database of
customers, manufacturers, and suppliers obtained between 2016 and 2020, which
remained operational on its ***SERVICE.1 or ***INTERFACE.1, despite the fact that its ***SERVICE.2 or ***INTERFACE.2 had been
closed in January 2021. This database continued to have
internet access without being disabled, and CECOTEC had not, at that time,
migrated the data contained on the old platform to the new
platform, nor had it applied the appropriate safeguards for data deletion or blocking. This platform was outdated and contained the vulnerabilities
recognized by CECOTEC, as stated in the Seventh Proven Fact of this proposal. This decision to maintain the old platform partially active
necessarily implies that the processing of personal data contained
therein would also continue, and therefore had to be carried out in accordance with the requirements and guarantees
stipulated in the GDPR.
Therefore, there is no doubt that CECOTEC, as the data controller
contained on said platform, had to comply with the obligations established in the
data protection regulations, which require it, among other things: (i) to prevent any
breach of the confidentiality of the personal data contained in its database;
(ii) to establish appropriate organizational and technical measures on said
platform to ensure the protection of the personal data contained therein; (iii) to detect and notify the supervisory authority of any personal data breaches
occurring and to communicate them to the affected parties, where applicable, within the timeframes and in the manner provided for in the GDPR.
It is thus confirmed, that CECOTEC was processing personal data of the
customers contained on said former online store platform, being responsible
for its processing in accordance with the concepts defined in Articles 4.1, 4.2 and 4.7
of the GDPR.
2.2. On the occurrence of a personal data breach and its
scope.
As a preliminary step to assessing the occurrence in the present case of the infringements
alleged in these proceedings, it is necessary to determine, first, whether the
breach that was notified to this Agency by CECOTEC on April 19, 2023, involved
unauthorized access by the cyber attacker to the data contained on the
said platform ***SOFTWARE.1 used by CECOTEC, which can be classified
as a personal data breach, within the meaning provided for in Article 4, paragraph 12
of the GDPR, which broadly defines “personal data breaches” as “all violations of the security caused by the
accidental or unlawful destruction, loss, or alteration of personal data transmitted,
28001 – Madrid 6 sedeagpd.gob.es 46/173
stored or otherwise processed, or the unauthorized disclosure of or access to
such data.”
As stated in the third and fourth proven facts of this proposal, in the present case it has been established during the investigation phase that CECOTEC
was the victim of a cyberattack that occurred on April 5, 2023, whereby a malicious actor was able to access without authorization the information contained in the table called
“***TABLE.1: Customer and Order Addresses” contained in the former
online store platform ***SOFTWARE.1.
As a consequence of this illegitimate access, a confidentiality breach occurred, affecting at least 1,000 records that were identified during the investigation as being in the possession of the malicious actor and offered for sale on a dark web forum. These records contained personal data belonging to 933 individuals with verified national identity card numbers, as recorded in the aforementioned official report of February 14, 2025. This personal data was not encrypted, and the cyber-attacker provided a sample in which all of it appears visible. According to the report, this data included:
Postal address (street, number, postal code, and city).
Identifying codes: address code, country code, customer code, as well as supplier and manufacturer identifier codes (which appear as 1 or 0 because they are linked to other personal customer data).
Name and surname
National ID number
Landline and mobile phone numbers
Therefore, the occurrence of a breach of confidentiality of personal data is confirmed, since, in accordance with Article 4.12 of the GDPR, a security breach of the platform occurred, resulting in the unauthorized communication of or access to said personal data.
In the assessment of the evidence and the response to the allegations against the initial agreement and the proposed resolution, the reasons why the commission of the four administrative infractions should be confirmed will be detailed, confirming the assessments made in the proposed resolution following the investigation. The respondent has not provided any documentary evidence in its allegations against the proposed resolution, nor any grounds justifying the dismissal of the case or the reduction of the sanctions proposed by the investigating officer.
III. Assessment of the Evidence
The respondent has submitted several documents throughout the preliminary investigation phase, and several documents in which it presents allegations against to the
initiation agreement of this case, and in response to the proposed resolution, and answers
the two requests for evidence that were agreed upon by this investigating judge on
June 3 and August 27, 2024.
28001 – Madrid 6 sedeagpd.gob.es 47/173
In the present case, in the written submissions to the initiation agreement,
CECOTEC acknowledged from the outset that a breach of
personal data occurred in one of its databases, originating from the cyberattack referred to
in the first proven fact of this proposal, and the facts asserted by CECOTEC regarding the characteristics of the platform
***SOFTWARE.1 that was the target of the cyberattack, and the lack of determination of the entry vector
of the cyberattack, have been deemed proven.
However, as the proposed resolution indicates, these were relevant
disputed facts of the proceedings whose accreditation required The evidentiary proceedings (evidence agreements of June 3 and August 27, 2024) included the following:
- The scope or number of people affected by the confidentiality breach.
- Whether CECOTEC acted culpable with respect to the data confidentiality breach alleged as an infringement of Article 5.1.f).
- The vulnerabilities detected and measures taken on the platform
***SOFTWARE.1 of CECOTEC's former online store before detecting the breach caused by the cyberattack.
- The corrective measures taken by CECOTEC after detecting the cyberattack.
Without prejudice to responding separately to the allegations made in the following legal basis, the proposed resolution analyzed, in its Legal Basis III, the evidence presented in these proceedings and determined the reasons and evidence on which the acknowledged and disputed facts of these proceedings were considered proven. Procedure.
3.1. Facts acknowledged by the defendant.
In light of the allegations made and documents submitted by the defendant (prior to the issuance of the proposed resolution), it was stated that the following facts, acknowledged by the defendant, were considered proven in the proposed resolution:
- Occurrence of a breach or leak of personal data contained in a former CECOTEC online store platform.
It is a fact acknowledged by CECOTEC that a breach of confidentiality occurred with the personal data contained in table “***TABLE.1”
of the former open-source platform ***SOFTWARE.1 version 1.6, used for the CECOTEC online store until the closure of its ***SERVICE.2 (…) in
2021, which continued to be used in its ***SERVICE.1 (…) at the time of the cyberattack (April 5, 2023).
28001 – Madrid 6 sedeagpd.gob.es 48/173
Thus, according to the first proven fact of this
proposal, INCIBE warned CECOTEC on April 5, 2023, that a malicious actor
had posted on that date in a dark web forum that they had
access to a database of a well-known Spanish appliance company,
whose financial data could correspond to
CECOTEC. This first cybersecurity incident alert was
received by CECOTEC's general inbox and was not forwarded to the
relevant department, as shown in the email provided as Annex
7, according to the fifth proven fact.
It is also established in the third proven fact that, after receiving a
second notification alert from INCIBE on April 12, 2023, CECOTEC's
cybersecurity director requested the information from INCIBE and initiated
the appropriate checks to verify the sample of 17 records that the malicious actor
had published in said forum, and sent an internal email to the Data Protection Officer of
CECOTEC dated April 14, 2023 (attached as Annex 6 to document
Resp#1), in which he indicated that the 17 records are included in the table
called “***TABLE.1” belonging to the platform ***SOFTWARE.1, which was
partially shut down in 2021, was outdated and suffered from
multiple vulnerabilities, whose ***SERVICE.1 remained active and with internet access (with username and password), and that only 6 of these corresponded
to data of real people, the rest also being included in the table, but
corresponding to test data.
It must be said that in this case, the company has maintained a contradictory version
regarding the plausibility of the cyber-attack, since:
o In its two written responses to the requests carried out
during the investigation phase: (i) on the one hand, they deny that the leak
is real, referring to the fact that the forum message does not mention
at any point that the database belongs to this organization
and, on the other hand, that the sample data contained in the published
screenshot is not sufficient to determine that there has been
a real leak of the company's database; (ii) and, on the other
hand, they acknowledge that these 17 records that appeared in the initial sample
match the data stored in one of their tables in the
database called “***TABLE.1”. And as a consequence, it is
noted that CECOTEC decided to notify this Agency of a breach of personal data
in its database produced as a result of the cyber-
attack, considering that this affected these 6 real people whose data was
contained in said table, although it does not consider it necessary to communicate
with those affected because it is not credible and classifies the breach as having
low risk and impact.
or But in the 2 Written statements of allegations submitted after the initiation agreement
- after requesting a copy of the file and learning that the cyber-attacker
provided this Agency with a sample of 1,000 records - CECOTEC
acknowledged that it had been the victim of a cyber-attack, which affected
only these 6 people, denying that its
culpability in the leak has been proven, and that the cyber-attacker has
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 49/173
the entire database contained in table “***TABLE.1”.
This version is maintained today, after the allegations made
against the proposed resolution.
Therefore, we can say that after the initiation agreement for this case and receiving
a complete copy thereof, CECOTEC acknowledges that it has been the victim of a
cyberattack, and that it has reported it to the National Police.
The complaint filed with the National Police dated May 13, 2024.
In her second statement of allegations, she indicates that she is filing a complaint after learning
from this Agency that the cyber-attacker had been contacted during the investigation phase, at which point she was able to obtain the contact information of the malicious actor. However, the truth is that this same information, which the inspector used
to contact the attacker during the investigation, was found in the first communication from INCIBE that the defendant received, which also provided the link to access the publication and suggested contacting the cyber-attacker.
According to the cybersecurity glossary published by INCIBE in 2021,
a cyberattack is defined as “the deliberate attempt by a cyberattacker to gain unauthorized access to a computer system by exploiting various techniques and vulnerabilities to carry out malicious activities, such as stealing information, extorting the owner, or simply damaging the system.”
As reflected in the third finding of fact, although initially the
defendant company stated that, while the 17 records in the first
sample contained in the advertisement matched, it could not confirm the plausibility of the
cyberattack, after the initiation of sanction proceedings and receipt of a copy of the
file, the defendant submitted three written arguments in which it
acknowledged that it had been the victim of a cyberattack (for which it considers itself
to bear no responsibility), whereby an unauthorized third party
gained access to one of the tables in its database, resulting in a
breach of confidentiality of the personal data contained on its platform,
which can be considered a recognized and proven fact, according to
the multiple pieces of evidence contained in the third finding of fact of this
proposal.
Thus, although prior to the draft resolution the number of records affected by the cyberattack was a matter of debate (the extent of the confidentiality breach), it was beyond doubt that this personal data breach occurred and that it affected the table “***TABLE.1” provided by CECOTEC on September 24, 2024, contained in the customized structure of CECOTEC's former online store platform, which was submitted as Annex 2 during the testing phase.
Following the proposed resolution, in which a copy of the Proceedings of February 14, 2025, was delivered to the respondent, comparing the sample provided to the inspector with table ***TABLE.1 provided by
28001 – Madrid 6 sedeagpd.gob.es 50/173
CECOTEC, the issue of the scope of the breach was established at 933 individuals, and has ceased to be a matter of dispute, becoming a fact acknowledged in the arguments against the proposed resolution, as will be explained later.
- Regarding the database targeted by the cyberattack in which the breach of personal data confidentiality occurred.
As stated in the second established fact, it is a recognized fact
that a cyberattack occurred affecting the former online store platform
named ***SOFTWARE.1 version 1.6, where the aforementioned table “***TABLE.1” was stored.
According to CECOTEC's statement in Response #1: “The platform was
an online store designed using the software ***SOFTWARE.1,
dedicated to the creation and management of virtual stores for e-commerce,”
it was hosted on the Amazon Web Services infrastructure,” and “the platform was
replaced by a new, internally developed online store that adopted
more modern open-source web development technologies (…) This
transition was completed in early 2021. Despite the closure of the
original platform, limited access to it (***INTERFACE.1) has been maintained
for the sole purpose of addressing requests, needs, and/or complaints from the company's clients.”
In document Resp#2, CECOTEC indicates that the reason the platform
is still accessible online is that the migration
of the integrations from the old platform to the new one has not yet been completed. They state that
INTERFACE.1 remains active due to: “the need to maintain active integrations
with our new online store. These integrations operate in read-only mode and
are essential for the functioning of our system, so updating the
platform to a more recent version could cause problems with them. Furthermore, some of these integrations still require that the platform's ***INTERFACE.1 be accessible from the internet. However,
in the coming months, the necessary technical steps will be taken
to migrate all platform integrations and completely eliminate
the platform's internet exposure.”
The basic structure of said platform corresponded to version 1.6, and has been
processed by this investigating officer on June 3, 2024, and the respondent has provided
the customized structure of said platform that was in effect on the date of the
cyberattack, which is attached as Annex 2 to its initial response
to the evidentiary agreement of July 4, 2024. Within said structure, it can be observed that there is
a table called “***TABLE.1: customer and order addresses” which was
requested and provided by the respondent on September 24, 2024, and which was the target of the cyberattack.
- Regarding the lack of determination of the entry point of the cyberattack.
It is also not disputed that the data controller has
been unable to determine the entry point of the cyberattack. As
28001 – Madrid 6 sedeagpd.gob.es 51/173
states in the seventh proven fact, this was reflected in the API report of the
inspector, accepting as true the checks carried out by the cybersecurity manager
of CECOTEC in the email of April 14, 2023
which is included as Annex 6 of document Resp#1, in which the DPD was informed
of the checks carried out to determine the certainty and entry vector
of the cyberattack:
“We also saw that said ***SOFTWARE.1 presented several version vulnerabilities
but we cannot determine if that is the entry vector,” and “After
analyzing all environments, the cybersecurity department cannot
determine if it was due to malware on a workstation or from the
web application itself, since we currently do not have any
system for monitoring equipment from the workstation, in addition to not having the
web application monitored.”
3.2. Disputed Facts in the Proceedings
The disputed facts, the existence of which was denied by the defendant before the proposed resolution was issued, were those that were the subject of evidence in these proceedings and are considered proven based on the following:
- The scope of said leak or breach of personal data (number of records affected by the breach).
Once the breach was acknowledged and notified, the main point of contention in the proceedings focused on determining the scope of the personal data breach, since the company acknowledged from the outset (in its breach notification of April 19, 2023) that the cyberattack on its platform affected six real individuals, but denied that the cyberattacker had access to all the records, or even to the 1,000 contained in the sample provided by the attacker when contacting the acting inspector. This issue has been addressed,
primarily, in the fourth finding of fact of this proposal.
In this regard, it should be clarified that the agreement initiating this sanctioning procedure
indicated that the initial analysis of the documentation in the file
revealed various pieces of evidence from which it could be deduced that the cyber-
attack was real and that there was a very high probability that the resulting breach
of personal data could have affected more than one million
records contained in the company's database. This high probability could be inferred
from the fact that the malicious actor confirmed that the database
belonged to CECOTEC, or that they had a sample of 1,000 records
whose fields and order exactly matched those of table ***TABLE.1
which CECOTEC claimed to have. But the truth is that the initial agreement did not establish the
initial penalty for the infractions based on a possible breach of almost 1 million
records or on the 1,000 records in this sample, but rather starting from the 17
records corresponding to 6 real people who had been reported as a
breach by the defendant, and noting that this was done “without prejudice to the possibility that
the investigation might reveal a greater number of affected parties.”
28001 – Madrid 6 sedeagpd.gob.es 52/173
Well, once allegations against the initial agreement were submitted, and the defendant having
denied that the breach affected more than 6 real people
contained in sample 1 of the malicious actor (of 17 records), the investigating officer
agreed to conduct an investigation in order to determine the extent of those affected by the
breach.
During the evidentiary phase, an initial evidentiary agreement was issued, after which it was possible to confirm the customized structure of the ***SOFTWARE.1 Platform
version 1.6 that was being used as an online store by CECOTEC
(Annex 2). In a second, expanded evidentiary agreement, CECOTEC was required to provide the complete content of the table called “***TABLE.1:
customer and order addresses” as it appeared on the date of the cyber-attack (April 5, 2023), in order to verify the claims made by
CECOTEC.
... In response to the expanded evidence agreement, CECOTEC submitted Table 1 on September 24, 2024. This table was analyzed and compared with the second sample of data obtained by the cyber attacker. The report also included a list of 100% matches between the records in both tables, submitted in the proceedings on February 14, 2025. This report yielded the objective data set forth in the fourth finding of fact of this proposal.
The following data, presented in said report, are particularly relevant for establishing the scope of the breach in terms of evidence:
- That the total number of records claimed by the malicious actor does not match the total number of records in Table 1 of CECOTEC. This allegation by the defendant should be upheld.
- But the 1,000 records included in the second sample provided by the
malicious actor correspond entirely to the contents of table
TABLE.1, and belong to a total of 933 individuals with verified ID numbers
, even matching the identifier codes automatically generated
by the database (customer ID, TABLE.1 ID, country ID, etc.).
This evidence obtained during the testing phase of the procedure is
conclusive and proves, without a doubt, as the proposed resolution indicates,
that the cyber attacker accessed this table in the CECOTEC database
and exfiltrated or extracted from it a minimum of 1,000 records, which
corresponded to the personal data of 933 individuals identified
in section 2.2 of this proposal, a fact acknowledged by the company
being sued in its response to the resolution.
Regarding the objections raised against the proposed resolution,
it should be clarified that the assessment of evidence carried out in the proposed resolution did not establish at any point that the cyber attacker
had access to more than one million records extracted from the aforementioned table. Two situations were distinguished:
28001 – Madrid 6 sedeagpd.gob.es 53/173
On the one hand, it was noted that there was a high probability that the cyber-
attacker could have accessed the 1,086,185 data records he claimed to have, because although this number does not match the total number of
records in table ***TABLE.1 (over 2 million), the fact is
that this did not exclude the possibility that he had accessed all of these
records: “because extracting a large number of data points like the
present one takes time and can be stopped or interrupted by various
causes, external or intentional, whether it comes from an external source through an
SQL injection or malware or workstation attack, or internally with
a username and password. Therefore, from a technical
point of view, it is possible and common for the cyberattack to be interrupted and not
to obtain all of the records contained in said table.”
However, from a legal standpoint, the proposal considered that
it could not be considered proven that the gap reached 1,086,185
records, because despite a high probability that this was the case,
sanctioning procedures require evidence based on a
degree of certainty, not probability. Therefore, it understood that this
number of records was not proven, since it was not possible
to obtain conclusive evidence regarding said number in
the present case: “given that the cyber attacker did not provide a
sample with all the records obtained for comparison, for which
obtaining would have required prior payment of the price demanded by the
same. The entire sample of the 1,086,185
records that the malicious actor claims to have is not available, so this Agency cannot
verify with certainty that all of this
data is in their possession. The evidence required in a
sanctioning procedure, the burden of which is attributed to the administration,
requires proving with certainty each disputed fact of the charge, which
harms the sanctioned party. And in this case, there is a high probability
but not a certainty, since a sample of the
total records that the malicious actor claims to have is not available, so it cannot be
compared with the original table of CECOTEC, and it is considered
proven that the resulting confidentiality breach affected more than
one million records. All of this in application of the Principle of Presumption
of Innocence and the Principle of in dubio pro reo.”
However, the proposal rightly pointed out that this is not the case for the
1,000 records contained in sample 2, which were obtained by the
inspector, regarding which, as the proposal states: “If there is
sufficient incriminating evidence to allow us to state with certainty that the malicious actor
accessed the 1,000 records contained in sample 2, which
was provided to the inspector. Since this Agency has said
sample and the original table ***TABLE.1 provided by
CECOTEC, and has been able to compare the data contained in
both.”
Based on this argument, the proposal considered it proven in the
fourth and sixth findings of fact that the breach had affected these
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 54/173
1,000 records, containing the personal data of 933 people who
were identified, which has been acknowledged by the respondent in
its written arguments against the proposed resolution, on the pages that have
been transcribed verbatim in the fourth finding of fact, last paragraph. In which
it is observed that the respondent assumes it has been proven that the breach affected
933 records and requests that the penalty be graduated based on these records,
focusing on dismissing the claim that the cyber attacker had access to the 1,086,185 records
that he claimed to have when he contacted the inspector, which is not a point of contention,
since the proposal had already clarified this issue.
Therefore, after the submission of arguments against the proposed resolution, it can be stated unequivocally
that the scope of the breach is limited to 933 people, and
that this is a fact acknowledged and not disputed by the respondent.
- . ... Another major point of contention raised by the defendant in its initial pleadings has been the fact that it has not been proven that the cyberattack resulted from negligent or culpable conduct on the part of CECOTEC. In its pleadings, it was argued that strict liability is not applicable in criminal law and that the principle of culpability must be applied. Furthermore, it was asserted that in this case, it has not been established that the leak or breach of personal data resulted from negligent conduct on the part of the company, which was the victim of a cyberattack. The defendant maintains this same interpretation in its response to the proposed resolution, introducing certain modifications that will be addressed in Legal Basis V.
Therefore, CECOTEC's culpable conduct has been a point of contention in the proceedings, which has also been considered proven through the evidence presented in the seventh finding of fact.
As the respondent points out, it is a requirement for imputing an administrative infringement under Article 5.1.f) of the GDPR, for breaching the duty to maintain the confidentiality of personal data, that, in addition to proving that there has been an unauthorized breach of personal data, it be proven that this breach was due to negligent actions by the company responsible for processing.
However, as the proposal has indicated, the duty of confidentiality is not only breached by failing to adopt measures that would have prevented the cyberattack from succeeding, but also by failing to protect the confidentiality of the personal data contained in the original database (at rest), by properly encrypting it to prevent the cyberattack from accessing its content, as it would be unreadable or undecipherable without the decryption key.
In this regard, it should be noted that when the proposed resolution stated that
"this allegation could be partially upheld," it was to acknowledge that, although the initial
agreement was based on the premise that there was evidence that the
28001 – Madrid 6 sedeagpd.gob.es 55/173
vulnerabilities and lack of protection of the platform could have
enabled the cyberattack, the fact is that, after the defendant denied this, and
the evidence was gathered during the investigation phase, there were still indications but
not enough certainty to definitively state that these
vulnerabilities and deficiencies were what allowed the cyberattack, since
the entry vector had not been established. Therefore, the proposed
resolution determined that this allegation was partially upheld, to establish
that it was not proven that the causal link of the exfiltration of personal data
that occurred through the cyberattack was the defendant's negligence.
But it is not true that the proposed resolution also acknowledged that
CECOTEC is not guilty of allowing the breach of confidentiality of
personal data. What the proposal actually stated was that—despite not being
able to be held responsible for the attack or unauthorized access because
the entry point could not be proven—it had been proven, and CECOTEC could be considered guilty, for not having encrypted the personal data that was
accessed and exfiltrated. Since encrypting personal data would have
prevented the cyber attacker from revealing its content and breaching
its confidentiality, preventing them from using it or knowing its content
even if they had gained access.
Thus, the proposed resolution expressly stated the following:
“The allegations made by CECOTEC can be partially upheld
regarding the fact that it could not be proven that the leak was possible
due to the existence of the aforementioned vulnerabilities and the lack of
the adoption of any of the organizational and technical measures that would have been
necessary to prevent unauthorized access to the data in the event of a
cyberattack.
However, the respondent is not taking into account the fact that the
duty to maintain the confidentiality of personal data and the duty to
adopt all appropriate organizational and technical measures to
guarantee it, is not limited solely to providing measures aimed at
ensuring that unauthorized access to personal data does not occur, but extends to adopting preventive measures that
prevent such personal data from being published or known by
those who access it unlawfully.
In other words, it is understood that the diligence required of the data controller
by Article 5.1.f) of the GDPR to comply with its duty of
confidentiality of personal data not only extends to the duty to
provide the necessary measures to prevent unauthorized access by
third parties (such as what happened in this cyberattack), but also to establish
appropriate measures for the pseudonymization and encryption of personal data,
carrying out a proper information encoding process to
prevent it from being disclosed and reaching unauthorized persons.
And this is precisely what has happened in the present case, where
the lack of encryption and pseudonymization of the personal data that
28001 – Madrid 6 sedeagpd.gob.es 56/173
were the target of the cyberattack has been proven by the following
evidence:
The objective fact that the two samples provided
by the cyber attacker appear visible and without encoding the
personal data of the clients to which they refer.
Combined with the fact that, when questioned during the preliminary investigation
phase regarding the measures security measures adopted at
at the time of the cyberattack, it has not stated, nor
much less proven, that it had adopted the measure of
encrypting the personal data on its platform.
Thus, as the initial agreement pointed out, there are
reasonable indications that the unauthorized access or cyberattack may have
occurred due to negligence on the part of the defendant in
using an obsolete and outdated version of the platform, which had been
unsupported since 2019, and suffered from multiple vulnerabilities that
affected both ***SERVICE.2 and ***SERVICE.1 of the platform,
one of which was classified as “critical”, and had been published in July
2022 by INCIBE and cyberattack alert bulletins, urging users to
download an update aimed at correcting this vulnerability and
preventing the cyberattacks that were occurring, without this being
detected and corrected by CECOTEC.
Specifically, the inspector had determined during the investigation that: (i)
the inspector's report revealed the presence of version vulnerabilities
in the platform, consistent with a potential entry vector for
the breach, for which the company would be responsible due to negligence ("it has been
established that this platform was based on an obsolete and
outdated version of the software ***SOFTWARE.1, with known
vulnerabilities, unsupported since 2019, and that it had an
administration section (***SERVICE.1) with public access via the internet
(although restricted by username and password)"); (ii) and issued a Procedural Report
dated November 2, 2023, stating that these vulnerabilities
affected both ***SERVICE.1 and ***SERVICE.2 of the platform
and attached screenshots that confirmed a critical vulnerability
detected on July 22, 2022, in version 1.6 of the platforms
***SOFTWARE.1 with web services.
However, it is true that, as has been demonstrated
in the seventh proven fact, neither during the investigation nor after the
proceedings carried out, has it been possible to prove that this was the entry vector
that allowed the cybercriminal to access the aforementioned database. And it was the lack of adequate traceability and breach detection measures
by the company—whose cybersecurity manager
acknowledges that he could not determine the entry vector because the
platform did not have a monitoring system and had even
disabled some logs—prevented it from being proven that these
vulnerabilities were the causal link that allowed the cyber attacker access to the
platform.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 57/173
Given the requirement of culpability, the responsibility for the cyber attacker's access cannot be imputed to the
defendant. an attack was possible and resulted
in unauthorized access by the malicious actor to the records
contained in the aforementioned table. The defendant's argument is valid on this
point. The omission of such measures constitutes a breach of the
obligation to establish appropriate technical and organizational measures to
guarantee a level of security appropriate to the risk, thus allowing for a
breach of Article 32 of the GDPR. However, it cannot justify the
company's negligent conduct regarding the occurrence of the breach or
leakage of personal data, which requires the imputation of the infringement
of Article 5.1.f) of the GDPR.
However, this does not mean that the defendant is not liable for the
infringement of Article 5.1.f) of the GDPR, since it has been proven that
there was a lack of due diligence on its part that could have prevented
the personal data on the platform from being exposed, published, or transferred to
third parties, even if the cyber attacker had accessed it, had it applied the corresponding technical encryption measures that would have prevented the extracted personal data from being
intelligible and decrypted. The defendant's negligent conduct focuses
here on the omission of its duty to adopt measures of “pseudonymization and
encryption of personal data,” which constituted a technical measure to
protect the confidentiality of the data, according to Article 32.1.a) of the
GDPR, which should have been applied to this processing due to its characteristics,
number of data subjects, number of personal data, direct access via
the internet, lack of updating and support, etc., and which was not adopted.
Therefore, the company is considered to have acted negligently, since it: (i) is not at fault for allowing the
cybercriminal to access and extract personal data; (ii) but rather is
at fault for failing to apply encryption and pseudonymization measures to the personal data contained in table ***TABLE.1 of said platform, which would have prevented the cyberattacker from knowing,
disclosing, publishing, or transferring the content of said data to third parties.
And in this second aspect of the duty of confidentiality, if there is a
negligent act for which the company is responsible, then
the infringement of Article 5.1.f) of the GDPR can be upheld, with the
company being guilty of the breach of confidentiality, not because the cyber attacker
was able to access the personal data contained on its platform,
but because the company had not applied the necessary
encryption and pseudonymization processes to the personal data, and this
non-compliance allowed the attacker to view and understand the
content of the data.
Finally, it should be added that in its arguments against the proposed resolution,
CECOTEC points out that in its letter of August 30, 2023, it demonstrated that two encryption measures had indeed been adopted on the platform, but that it has not been
considered proven in the seventh fact that the personal data contained in the database had been encrypted.
28001 – Madrid 6 sedeagpd.gob.es 58/173
in "rest" that was
hosted on the defendant's servers, for the reasons set forth below:
The defendant claims that it had previously demonstrated that two data encryption measures for the platform had been adopted:
(...).
In the aforementioned document submitted on August 30, 2023, the defendant
states that they used the AWS platform as infrastructure, and to host
the database they used the Amazon RDS service, which refers to
the platform's database backups. There is no
explicit reference to Amazon RDS encrypting the backups,
nor is any documentation provided to prove it. Therefore, it is not
true that this fact has been proven, given that the Amazon RDS service does not encrypt database backups by default; rather, this must be expressly configured
when creating the database instance, and the defendant has not
proven that it performed said configuration. Encrypt the
backups.
However, even if proof were provided and it were
true that the database backups are being encrypted,
this would be an additional security measure to the encryption of the
original or "at rest" database itself, which must also be done
and is essential, since in this case the cyberattack did not
target the backups stored on Amazon
RDS, but rather the data contained in the
database or platform ***SOFTWARE.1, which is stored on the company's
servers. It has been proven that this data was neither
encrypted nor pseudonymized, given that both samples
provided by the cyber attacker show the same data in a
visible and intelligible manner.
• Communication between the access devices and the platform
was encrypted using TLS 1.2 or higher, which ensured the
protection of data in transit.
No proof is provided, although it is true that the use of
This TLS 1.2 communication protocol allows that when personal data is transmitted from one of the devices with access to the source or at-rest database to a destination device, the personal data "in transit" is transferred over an encrypted channel, protecting the personal data only while it is being transmitted.
However, if the personal data at rest (which is being sent) is not encrypted, the encryption lasts only while the message is being transmitted and is decrypted again when it reaches the destination. Therefore, if the data stored at rest is not encrypted, encrypting the transmission channel is an additional security measure that does not guarantee the confidentiality of the data, since the device receiving the message will obtain it in the same state as the original database.
In short, it cannot be considered proven that the defendant adopted measures to encryption on the at-rest database containing the exfiltrated personal data, since, even if it were true that the
defendant had adopted these measures, they would not be measures for
encrypting the at-rest database, but rather refer to the encryption of the
backups hosted on Amazon Web Services, or to the communication protocol
between devices in cases where information is transferred, which in no way replaces the requirement to adopt the
primary encryption measures, which must be applied to the active database itself
where the personal data is contained, which is not demonstrated in this
case.
Therefore, and given that all the personal data was exposed and visible in
the two samples obtained from the cyber attacker, it is beyond doubt that the
encryption of the personal data contained in the at-rest database within
the defendant's servers had not been applied, since otherwise the
cyber attacker would not have been able to decrypt the personal data contained therein.
It is understood, Therefore, the defendant's guilt being established, the causal link
of the breach of confidentiality of the personal data accessed
and exfiltrated by the cyber attacker being the failure to adopt encryption and
pseudonymization measures on the original or at-rest database where the affected personal data was stored, the encryption of which would have prevented
the cyber attacker from knowing the content of this data and using it,
as they did.
- Regarding the vulnerabilities and deficiencies of the ***SOFTWARE.1 platform as of the
date of the cyberattack.
In its statement of allegations against the proposed resolution of March 18,
2025, CECOTEC does not raise any allegations that question the existence of the
proven facts in relation to the vulnerabilities and deficiencies of the
platform on which the personal data subject to the cyberattack was hosted, nor
provide any new documentation in this regard (beyond the two encryption
measures already mentioned). reference), but rather limits itself to raising
legal questions that will be answered in Legal Basis V
of this Proposal.
Therefore, the proven facts that have been
recorded in proven fact eight are considered established, based on the reasons stated
in the proposed resolution, which are transcribed below.
<<The existence of vulnerabilities in the version of the platform that was
28001 – Madrid 6 sedeagpd.gob.es 60/173
used at the time of the cyberattack was acknowledged from the first written response
from CECOTEC, which included in its Annex 6 the email sent
to the DPO by CECOTEC's own Security Director in his email of April 14,
2023. And these were provided in the first written response of the investigation.
In this email, CECOTEC's Cybersecurity Director states that he cannot
clearly determine the entry vector of the cyberattack, due to the lack of
any system for monitoring equipment on the attacked platform, having
disabled the logs, and acknowledges that the platform suffered from vulnerabilities:
“After analyzing the logs of the image posted on the
forum, it was found that they match those of the company's old store
(…) which was closed in 2021 but is still used by some people
in search mode.”
We also tried to view the logs to trace the attack and uncover the
attacker, but we couldn't get anything clear since they only showed
user logins. Furthermore, some logs were disabled at the time for
performance reasons. At the server and database level,
we couldn't see much since it wasn't being monitored.
We also saw that said ***SOFTWARE.1 presented several
version vulnerabilities, but we cannot determine if that was the
entry vector.”
“After analyzing all environments, the cybersecurity department cannot
determine if it was due to malware on a workstation or
from the web application itself, since we currently do not have any system for monitoring equipment from the
workstation,
and the web application is not monitored.”
However, in the second written response to the investigation request,
CECOTEC denies or downplays the existence of any of these vulnerabilities or
deficiencies detected at the time of the cyberattack, stating that it had adopted
security measures regarding them, and providing documentation. And in its
written arguments against the initial agreement, it does not provide new documentation
regarding the measures adopted, but does request that they be considered
as a mitigating factor.
As stated in the eighth proven fact of this proposal, once
the documentation provided and the statements of the
defendant have been examined, it should be noted It has been established that, as of the date of the breach or
cyberattack (April 5, 2023), the ***SOFTWARE.1 platform suffered from the following
vulnerabilities and deficiencies:
1. Regarding the Platform's "version vulnerabilities,"
According to the Cybersecurity Glossary published by INCIBE, a
"vulnerability" is defined as a weakness or flaw in a system that can be exploited
for malicious purposes (usually through a program called a
28001 – Madrid 6 sedeagpd.gob.es 61/173
exploit). When discovered, the software or hardware developer will fix it by releasing a product security update.
CECOTEC acknowledges its involvement in its initial response, as
the cybersecurity manager stated in the aforementioned email of April 14, 2024. However, in its second response,
CECOTEC indicates that the vulnerabilities only affected its ***SERVICE.2, which was inactive, and not
SERVICE.1, which was active and had direct internet access.
To verify this specific point of contention, the inspector of the
procedure accessed the platform URL provided
by the defendant and issued a report dated November 2, 2023, stating
the following:
(i) Version 1.6.1 of ***SOFTWARE.1 is an outdated version, unsupported since 2019, and contains multiple critical vulnerabilities that affected both ***SERVICE.2
(user interface) as well as ***SERVICE.1 (…).
(ii) This platform, despite being outdated and undergoing migration,
remained active, providing direct internet access with a
username and password, even as of November 2,
2023. Although the company states that this access was to the
SERVICE.1 portion (claiming this was necessary due to integration requirements
with the newly implemented platform), and indicates that a data migration process to the new
platform is pending.
The inspector attached screenshots to this report, which show:
(i) A vulnerability notice for the ***SOFTWARE.1 platform, published on July 26, 2022, on the INCIBE website, stating that
***SOFTWARE.1 has released a security update that
corrects a critical vulnerability, therefore updating
the latest version available as soon as possible,” which specifically affects
version 1.6, used by CECOTEC.
(ii) Publication on the cybersecurity newsletter page
“Hispasec One a Day,” where this same warning appears regarding:
“Attackers actively exploit RCE vulnerability in the CMS
***SOFTWARE.1 of July 28, 2022. Cybercriminals find a
way to use an SQL injection vulnerability to
execute remote code on servers containing web services of
***SOFTWARE.1”
(iii) Publication of the announcement by ***SOFTWARE.1 that the Platform would
be discontinued after 2019.
For this reason, it is established in the eighth proven fact of this proposal
that:
(i) The vulnerabilities or lack of preventive measures detected at
the date of the cyberattack affected both ***SERVICE.1 and
***SERVICE.2 of the platform.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 62/173
(ii) That the platform has been out of support since 2019.
(iii) Furthermore, that on July 26, 2022, a vulnerability notice was published on the website of
***SOFTWARE.1 regarding the
same version of the ***SOFTWARE.1 platform used by
CECOTEC, through which cybercriminals were accessing
servers containing web services of this platform via
an SQL injection attack. Therefore, it was necessary to obtain the
update published by ***SOFTWARE.1 to
correct the vulnerability. CECOTEC acknowledged that it had not
updated the platform since 2019.
2. Secondly, in its second written response, CECOTEC raises
the question of whether traceability measures existed
on the platform beforehand, since CECOTEC maintains In their written statement:
Response #1 states that, as of the date of the cyberattack: “before receiving notification from INCIBE, the platform already had robust measures in place to ensure the traceability of actions taken in accessing both the platform and the database management system.” These measures were
designed to guarantee the security and integrity of the data, as well as
to detect any suspicious activity early.”
Regarding the database management system, it is stated that there were
measures restricting direct access from the internet and logs
monitoring access and activity in the database, but these are neither
detailed nor documented. Nor is there any evidence of the
tracing measures allegedly adopted before the cyberattack, but rather
of those adopted afterward.
Therefore, since no evidence has been provided of other measures adopted
prior to the cyberattack, it must be considered proven that
adequate traceability measures had not been adopted on the platform at the time
of the breach, given that:
- The email sent by the cybersecurity officer who analyzed the
platform on April 14, 2023, acknowledged the following:
“We tried to view the logs to see the traceability and uncover the attacker, but We were unable to draw any conclusions, as we reviewed the logs for ***SOFTWARE.1 and they were not very useful,
since they only showed user logins. Furthermore, some logs recorded by the CMS were deactivated at the time due to performance issues,
and were never reactivated.
- In addition, CECOTEC's Response #1 acknowledges that the platform did not have appropriate security measures in place regarding user access control, stating that:
“(...)”
3. Regarding the lack of updated platform risk analysis.
In this respect, as stated in API Report point 8: “the existence of a documented analysis carried out on April 10, 2022, has been
proven.
28001 – Madrid 6 sedeagpd.gob.es 63/173
The company confirms that there are no risk analyses with a date prior to the aforementioned date; however, It has been established
that the processing activity affected by the breach began in 2013
“Customer Management”).
This is established because in Response #1, CECOTEC provides an AR dated
April 10, 2022, and in Response #2 confirms that they did not carry out any previously,
they indicate that the platform has been operational since 2013, and provide two
unsigned updates from 2022 and 2023, and acknowledge that the
company is currently undergoing a document review and decision-making process
regarding measures to be taken: “The Spanish Data Protection Agency (AEPD) is informed that, in the last year, the position of
Data Protection Officer has been held by three different people,
there being no continuity in the functions of the Data Protection Officer
specified in Article 39 of Regulation 2016/679 of April 27, 2016 (hereinafter,
“GDPR”). Therefore, the company is currently undergoing an
urgent document review and decision-making process regarding measures to be taken and
procedures to be implemented, including the review of all the
risk analyses carried out and the assessment of the need to perform an
impact assessment of the same.
Regarding the lack of implementation of an adequate protocol for detecting and managing personal data breaches.
It is also established that the company did not adopt the necessary measures to ensure the implementation of a breach management protocol, since:
(i) In response #1, an internal document entitled
“Security Incident Management Protocol” is provided, which is unsigned and dated April 22, 2021. It does not contain the contact information
of the individuals to whom cybersecurity incident alerts should be communicated and those responsible for detecting and reporting the breach. Furthermore, there is no record that it was communicated to company personnel prior to the breach.
(i) When the "2022 update" cited by the
respondent was requested, the respondent submitted, in Response #2, a Security Breach Management Protocol, which is unsigned and dated
after the breach occurred and was detected ("Date of
last update: August 29, 2023"). This protocol is considered
adopted as a corrective measure but did not exist as a
preventive measure at the time the confidentiality breach
referred to in this case occurred, as
confirmed by the facts and the statements contained in this
same document, Response #2:
5. Failure to implement encryption measures for the personal data contained
in the database where the confidentiality breach occurred.
From the seventh proven fact, it follows, as already stated, from the content of
the sample published in the advertisement (which masked the name and surnames,
publishing and exposing the rest of the personal data contained in the
28001 – Madrid 6 sedeagpd.gob.es 64/173
table), and from the sample provided by the malicious actor to the
inspector on August 4, 2023, in which the 24 fields contained in table ***TABLE.1, which was the target of the
cyberattack, appear visible and unmasked, it follows that CECOTEC had also not adopted the essential measure
of pseudonymization and encryption of personal data contained in
said table ***TABLE.1. This is corroborated by the fact that CECOTEC
does not mention encryption and pseudonymization among the measures adopted regarding
the data contained on the platform.
However, as previously clarified, the attributable non-compliance
for not adopting these types of measures should not be considered when assessing the
infringement of Article 32 of the GDPR, but rather that of Article 5.1.f) of the GDPR.
- Regarding the preventive measures adopted on the platform before the
breach occurred.
In its statement of objections to the proposed resolution of March 18,
2025, CECOTEC does not raise any objections that challenge the
established facts regarding the preventive measures
adopted on the platform hosting the personal data subject
to the cyberattack, nor does it provide any new documentation in this regard (beyond the
two encryption measures already mentioned). Instead, it merely
raises legal questions that will be addressed in Legal Basis V of this Proposal.
Therefore, the proven facts set forth in the eighth proven fact are considered established, based on the reasons set forth in the proposed resolution, which are transcribed below.
In light of the documentation submitted to the proceedings, it is considered established that, as of the date of the cyberattack, the platform had the following preventive measures in place, as recorded in the API report and derived from the documentation submitted in Response #1:
or (…)
- Regarding the corrective measures adopted on the platform after the breach.
In its written submissions against the proposed resolution of March 18, 2025, CECOTEC does not raise any objections challenging the corrective measures adopted on the platform following the cyberattack, which were considered proven in the ninth finding of fact, nor has it provided any new documentation in this regard (beyond the two encryption measures already mentioned). Instead, it merely raises legal questions that will be addressed in Legal Basis V of this proposal.
Therefore, the proven facts stated in the ninth finding of fact are considered established, based on the reasons set forth in the proposed resolution, which are transcribed below.
28001 – Madrid 6 sedeagpd.gob.es 65/173
During the investigation phase of this case, CECOTEC stated
that it had taken corrective measures for the deficiencies observed in the
***SOFTWARE.1 platform once it became aware of the cyberattack,
providing some of the supporting documentation, which was
taken into account by the inspector when issuing his report, declaring them
substantiated in the seventh conclusion thereof.
Subsequently, in its first written submission of allegations against the initial agreement,
CECOTEC requests that these be considered as mitigating factors, providing a
list of corrective measures different from that provided up to that point in previous submissions, which is not accompanied by supporting
documentary evidence. Specifically, the following is noted:
“Since corrective measures were already adopted and communicated to the Spanish Data Protection Agency (AEPD) throughout the preliminary investigation phase, without being
requested by the AEPD, their scale and mitigation should be considered.
The following measures were subsequently adopted and
communicated to the AEPD:
1. Measures aimed at increasing employee awareness:
• Training, campaigns, and phishing drills.
• Emails
Evidence: Data protection training reports
2. Security measures regarding the platform:
• (…)
3. Identification and Assessment of Legal Risks
Identification and Assessment of Security Breaches
Evidence: Excel spreadsheet of risk analysis
4. Definition of data retention periods.
5. Implementation of mechanisms to regulate and verify the suitability and
compliance with obligations by data processors.
6. (…)
8. Creation of a security breach protocol for
employees.
9. (…)
10. A Security Committee has been established, comprised of the Data Protection Officer, the Cybersecurity Officer, the
Head of the Legal Department, the Head of the
IT Department, the CECOTEC Technology Manager, and a
member of the IT Department; with the objective of (…)
Evidence: Cecotec has a Security Committee Regulation.
In its arguments against the initial agreement, CECOTEC provided a
list of corrective measures whose adoption cannot be considered
proven, given that: (i) it includes the preventive measures that had been
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 66/173
adopted before the breach, as had been proven in the investigation phase, which cannot be considered corrective; (ii) it mentions
new measures but provides no supporting documentation for them;
iii) it also fails to reference the dates on which each of the related measures was adopted, so that this administration can
verify whether these measures could be considered mitigating factors for
being adopted before it became aware that an investigation had been initiated, as the respondent alleges.
Consequently, the adoption of the following corrective measures, as stated in the proven fact, has been deemed to have been duly proven:
eighth:
- Those alleged in the written responses during the investigation phase, the veracity of which was confirmed by the inspector, who stated the following in the conclusion of his report:
“After detecting the security breach, the following reactive measures were adopted to strengthen the platform's security:
(…)
- Following the initial agreement, access to the platform from the internet was disabled.
In its AlegAI#1 document, the respondent states that it disabled
access to the ***SOFTWARE.1 platform from the internet, which has been
verified by this investigating officer through a report dated June 3,
2024. Therefore, this corrective measure by
CECOTEC is considered proven after the initiation of the sanctioning procedure.
It is also established that the platform remained accessible via
the internet until at least November 2, 2023, the date on which the
inspector issued a report stating that: “access to the URL
***URL.1 remains available, allowing access to ***SERVICE.1 of the
software ***SOFTWARE.1 installation.” Having acknowledged
CECOTEC in its Response #2 that: “The reason why the
platform is still accessible on the Internet lies in the need to
maintain active integrations with our new online store. These
integrations operate in read-only mode and are essential for the
functioning of our system, so updating the platform to
a more recent version could cause problems with them.
Furthermore, some of these integrations still require that the platform's ***INTERFACE.1 be accessible from the Internet.
Notwithstanding the above, in the coming months, the necessary technical steps will be taken to migrate all
28001 – Madrid 6 sedeagpd.gob.es 67/173
platform integrations and completely eliminate the platform's exposure on the Internet.”>>
IV
Response to the allegations against the initiation agreement
Before the proposed resolution of the case was issued, the defendant company submitted
several written allegations Responding to the initial agreement and the
two evidentiary orders issued in these proceedings:
- Allegations to the initial agreement submitted on April 25, 2024, before receiving the
copy of the case file (AllegAI#1). These allegations list various grounds for
allegation, without providing any supporting documentation.
- Supplementary allegations submitted on May 8, 2024, after receiving the copy of the
case file (AllegAI#2). No documentation is provided, but the
filing of a criminal complaint for having been the victim of a cyberattack is announced,
which is subsequently attached in a document dated May 13, 2024 (Doc AlegAI#2).
In assessing the evidence, the proposed resolution of the case file addressed, in
Legal Basis III, the allegations made in the two briefs
submitted in response to the evidentiary agreements, dedicating
Legal Basis IV to the response to the two briefs of allegations against the
initiation agreement, the reasoning of which is fully endorsed by this Agency and is transcribed below:
<<4.1. Response to the first brief of allegations against the initiation agreement.
On April 25, 2024, before receiving the requested copy of the case file and before the deadline for submitting allegations had expired, the respondent submitted the main allegations of the
procedure as a precautionary measure (AllegAI#1), adding in the second brief of
allegations those related to the documents contained in the copy of the
case file.
This initial statement of objections to the initiation agreement does not include any supporting documentation and requests the dismissal of the case file and the opening of a new period for submitting objections,
stating, based on one preliminary objection and six subsequent objections:
The reasons why the objections should be dismissed are set forth below,
in light of the proven facts that have come to light
during the investigation and the applicable regulations that are the subject of this review:
PREVIOUS OBJECTION. VIOLATION OF THE LEGALLY ESTABLISHED PROCEDURE. INFRINGEMENT OF ARTICLE 24 OF THE SPANISH CONSTITUTION.
The respondent states that she did not receive a copy of the case file at
28001 – Madrid 6 sedeagpd.gob.es 68/173
the time she submitted the objections (April 25, 2024), alleging that this results in
a lack of due process, constituting nullity
by operation of law due to the absolute absence of the procedure. And by virtue of this,
through “FURTHERMORE, FIRST” they request that a period for supplementary allegations be opened.
It is understood that there has been no violation of the established procedure, nor of the
right to defense under Article 24 of the Spanish Constitution, since when the respondent
submitted this statement of allegations, she had been electronically notified
of the extension of the deadline and the submission of a copy of the file dated April 17,
2024, at the designated electronic address (which was received on April 18, 2024), although
the copy of the file was still pending delivery, and it was
advised that due to its size it could not be sent electronically, but rather to the
designated postal address for notification purposes, which did not occur
until April 30, 2024.
Therefore, when these initial allegations were submitted, the deadline for submitting allegations had not yet expired, its calculation being suspended until the
delivery of the copy of the file. All of this was expressly clarified to the claimant in the explanatory document regarding the extension agreement and delivery of a copy, dated April 30, 2024, attached to these proceedings. In it,
for her peace of mind, it was expressly stated:
“It is hereby noted that the deadline for submitting arguments against the initial agreement will end five business days after the notification of the extension agreement and delivery of a copy, which was sent by mail today. Therefore, without prejudice to the arguments submitted on April 25, 2023, being considered as having been filed,
it is clarified that a written statement of arguments against the initial agreement may be submitted within said deadline.”
Since the aforementioned deadline had not yet passed when the respondent decided to
submit the aforementioned allegations, and having submitted new ones on
May 8, 2024, after receiving the requested copy, it is understood,
furthermore, that no prejudice has been caused to the respondent, given that, in addition to
the extension of the deadline for submitting allegations having been granted and the
deadline having been calculated in the most favorable manner to the respondent, as well as being informed that it could submit
supplementary allegations after receiving the copy of the file, the respondent
has submitted them, and these have been admitted and are taken into account in
this proposed resolution.
FIRST.- VIOLATION OF THE PRINCIPLE OF NE BIS IN IDEM BY
SANCTIONING THE SAME CONDUCT TWICE WITH RESPECT TO THE
INFRINGEMENTS CONTEMPLATED IN ARTICLES 5.1. F) AND 32 OF THE
GDPR.
CECOTEC expresses its disagreement with the classification of the facts
28001 – Madrid 6 sedeagpd.gob.es 69/173
carried out by the Spanish Data Protection Agency (AEPD) under Article 5.1.f) and Article 32 of the GDPR, since
in its opinion, this implies sanctioning the same conduct twice, based on
the following:
o According to Guidelines 04/2022 of the European Data Protection Board (hereinafter,
“EDPB”) on the calculation of fines under the GDPR (hereinafter,
EDPB Guidelines 04/22), the provisions invoked by the AEPD in
this sanctioning procedure would protect the same legal interest, namely, the adequate security of personal data,
and it is therefore illegal to sanction the offender twice for the same offense. In this regard,
the Judgment of the Austrian Federal Court (Ra) No. 2018/02/1023, paragraph 7, is cited. CECOTEC then goes on to point out that: “In the present case, the protected legal interest
(data confidentiality) is the same. The Spanish Data Protection Agency (AEPD) focuses both
infringements on the fact that adequate technical and organizational security measures have not been adopted, which has affected the ability
to guarantee confidentiality,” which implies a violation, according to the
EDPB Guidelines, of “the ‘consumer principle’ or that one infringement is
a precursor to another.”
or Furthermore, in the opinion of this party, there would be a violation of the principle of double jeopardy (non bis in idem), according to the criteria of the National Court (among others: Judgment of the National Court of July 23, 2021 (appeal no. 1/2017). The Order of the Supreme Court (Administrative Chamber),
Section 1, of July 13, 2023, appeal no. 3120/2023, is also cited.
or Finally, the application of the sanction contained for cases of concurrent offenses in Article 29 of Law
40/2015, of October 1, on the Legal Regime of the Public Sector (hereinafter, the “LRJSP”) is alleged: 5. When the commission of one offense necessarily leads to the commission of another or others, only the sanction corresponding to the most serious offense committed shall be imposed.
First, it should be noted that the three alleged violations of the
claim refer to the possible breach of the same principle,
namely, the “Ne is idem Principle” enshrined in Article 9.3 of the
Constitution, which establishes as a general rule that the same conduct may not be punished
twice; its manifestation in the sanctioning sphere within the Spanish legal system is found in
Article 31 of the LRJSP. And finally, the aforementioned Article 29 of the LRJSP,
establishes a rule for imposing the most severe sanction in cases where
what is doctrinally known as a medial concurrence of
offenses occurs, with the “Principle of specialty, subsidiarity, or consumption” being one of the applicable rules for resolving concurrences of offenses.
28001 – Madrid 6 sedeagpd.gob.es 70/173
referred to in the EDPB Guidelines 04/2022 on the calculation of fines.
28001 – Madrid 6 sedeagpd.gob.es
70/173 The EDPB Guidelines 04/2022 (Guide to Fines), cited by the
respondent, translate the general theory on the rules of actual,
medial, or ideal concurrence of infringements applicable in Spanish administrative law
to the terminology used by the GDPR in matters of
data protection, distinguishing three types of situations in section 3.1:
“3.1 — A single sanctionable act
25. As a first step, it is essential to determine whether there is a single
sanctionable act (“idem”) or multiple acts in order to identify the relevant
sanctionable conduct that should be fined. It is therefore important
to understand which circumstances are considered as one and the same act,
rather than multiple acts. The relevant sanctionable conduct
must be assessed and identified on a case-by-case basis. (…)
29. If it is shown that the circumstances of the matter constitute a single
act and give rise to a single infringement, the fine may be
calculated on the basis of that infringement and its legal maximum. However,
if the circumstances of the case constitute a single
conduct, but this conduct gives rise not only to one, but to
multiple offenses, it must be determined whether the imputation of one offense
precludes the attribution of another offense (chapter 3.1.1) or whether they can be
imputed to each other (chapter 3.1.2). When the circumstances of the case
constitute multiple acts, they will be considered a plurality of actions and
will be dealt with in accordance with chapter 3.2.
3.1.1. Concurrence of Offences
30. The principle of concurrence of offenses (also called “apparent
concurrence” (See, for example, the judgment of the Austrian
Verwaltungsgerichtshof, Ra 2018/02/0123, paragraph 9) or “false
concurrence”) applies whenever the application of one provision
prevents or subsumes the applicability of the other. In other words, The
concurrence already occurs at the abstract level of legal provisions.
This could be due to the principle of specialty, subsidiarity, or
consummation, which often applies when provisions protect the
same legal interest. In such cases, it would be illegal to sanction the
offender twice for the same offense.
In such a case of concurrent offenses, the amount of the fine should only
be calculated on the basis of the selected offense according to
the previous rules (overlap of the offense).
“Principle of Speciality
32. The principle of specialty (especialia generalibus derogant) is a
legal principle that means that a more specific provision (derived
from the same legal act or from different legal acts of the same force)
replaces a more general provision, even though both pursue the same
objective. The more specific offense is sometimes considered a
"qualified type" of the less specific one. The qualified type of offense
could be subject to a higher level of fine, a higher statutory maximum
or to a longer limitation period.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 71/173
33. However, sometimes, through interpretation, the principle of specialty can also be applied when, for reasons of nature and systematics,
an infringement is considered a restriction of an apparently more
specific one, even though its wording alone does not explicitly mention an
additional element.
34. When, on the other hand, two provisions pursue independent objectives,
this constitutes a differentiating factor that justifies the imposition of separate fines.
For example, if an infringement of one provision automatically leads to
an infringement of the other, but the reverse is not true,
these infringements pursue independent objectives.
35. These principles of specialty can only be applied to the extent that
the objectives pursued by the infringements in question are
truly congruent in the specific case. Given that the data protection principles of Article 5 of the GDPR These are established as general concepts.
There may be situations in which other provisions are a
concretization of this principle, but without circumscribing the principle in its
entirety. In other words, a provision does not always define the
full scope of the principle. Therefore, depending on the circumstances, in
some cases they overlap congruently and one offense can
substitute for the other, while in other cases, the overlap is only
partial and, therefore, not entirely congruent. To the extent that they are not
congruent, there is no concurrence of offenses. Instead, they can be
applied side by side when calculating the fine.
Principle of Subsidiarity
36. Another form of concurrence of offenses is often called the
principle of subsidiarity. It applies when one offense is considered
subsidiary to another offense. This could be because the law formally declares
subsidiarity or because subsidiarity arises for
material reasons. (...)
Principle of Consumption
37. The principle of concurrence applies in cases where the infringement of
one provision regularly leads to the infringement of another, often
because one infringement is a precursor to the other.
3.1.2 — Unity of action — Article 83(3) of the GDPR
38. Similar to the situation of concurrent offenses, the principle of unity
of action (also called “ideal concurrence”) applies in
cases where conduct falls under several legal
provisions, with the difference that one provision is neither excluded nor
subsumed by the applicability of the other, because they do not fall within the scope of
the principles of specialty, subsidiarity, or concurrence and
primarily pursue different objectives. (…)
(…) In the case of unity of action, the total amount of the administrative fine
shall not exceed the amount specified for the most serious infringement. “With regard to the interpretation of Article 83(3) of the GDPR, the
EDPB notes that The principle of "effet utile" requires that all institutions
give full force and effect to EU law.16 In this respect, Article
83(3) of the GDPR should not be interpreted in a way that
"it would not matter whether an infringer committed one or multiple infringements of the
GDPR when assessing the fine" (...)
3.2 — Multiple Sanctionable Conduct
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 72/173
44. The principle of multiple actions (also known as
"Realkonkurrenz", "factual concurrence", or "coincidental concurrence")
describes all cases not covered by the principles of concurrence
of offenses (chapter 3.1.1) or Article 83(3) of the GDPR (chapter
3.1.2).
45. The only reason these infringements are addressed in one decision
is because they came to the attention of the supervisory authority simultaneously
without being the same or linked processing operations within the meaning of
Article 83(3) of the GDPR. Therefore, the infringer is deemed
to have infringed several legal provisions, and separate fines are imposed
in accordance with the national procedure, either in the same fine decision or in
separate fine decisions. Furthermore, since Article
83(3) of the GDPR does not apply, the total amount of the administrative fine may
exceed the amount specified for the most serious infringement (argumentum e contrario).
Cases involving multiple actions do not provide any grounds
for granting preferential treatment to the infringer with regard to the calculation of the fines. However,
this is understood without prejudice to the obligation to continue
respecting the general principle of proportionality. (...)
We see, therefore, that Guidelines 04-2022 on calculating the guideline for
fines do not refer in any way to the infringements of
Article 5.1.f) and 32 of the GDPR having the same protected legal interest, but rather
that this is an interpretation made by the respondent itself of the general rules
set out in section 3.1.1 on “Concurrence of
offenses”.
The respondent argues that: “In the present case, the protected legal interest
(data confidentiality) is the same. The Spanish Data Protection Agency (AEPD) focuses
on both infringements the fact that adequate technical and organizational security measures have not been adopted, which has affected the ability to
guarantee confidentiality. This undoubtedly leads us, in accordance with
Guidelines 04/2022 of the European Data Protection Board, to the concurrence
of the ‘principle of absorption,’ or that one infringement is a precursor to the other.”
The respondent maintains that the Principle of Absorption should be applied
because this is a case of “concurrence of offenses” (equivalent to
the medial concurrence of infringements under Spanish law). But part two
erroneous premises in considering that in this case there is only one conduct
(or rather, one omission), which is the lack of adoption of security measures
on the ***SOFTWARE.1 platform to protect confidentiality) that
is violating two regulations (Article 5.1.f) and Article 32 of the GDPR), which protect
the same legal interest (the confidentiality of personal data as
claimed), and that therefore, we must apply the Principle of Absorption
to which the EDPB refers.
But for there to be a “concurrence of offenses,” the CEPD requires the fulfillment of two conditions that are not met in the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 73/173
present case: that we are dealing with a single action/omission that
constitutes a breach of two provisions, and furthermore, that both provisions or
administrative infringements protect the same legal interest.
- First, in this case we are not dealing with a
"concurrence of offenses" but rather with what the EDPB refers to as
a "plurality of actions" or "multiple infringing conduct"
(real concurrence of infringements according to Spanish
administrative law) which justifies charging two
separate administrative infringements, and that these be sanctioned
separately, since, as mentioned in the
assessment of the evidence, in this case, there are two
infringing conduct or breaches of duties by the data controller
(omissions) that must be distinguished:
(i) Within the infringement of Article 5.1.f) of the GDPR, as already
explained, the proven negligent conduct that is
attributed to the respondent is the omission of the duty to
pseudonymize and encrypt the personal data contained
in table ***TABLE.1 of the platform ***SOFTWARE.1.
This infringement does not allege liability for
failing to adopt the appropriate security measures under Article 32
of the GDPR to prevent the
extraction or leakage of personal data, but rather for failing to
adopt measures that would have prevented the cyber-
attacker from viewing or understanding the extracted personal data,
as well as publishing or transferring it to third parties.
(ii) However, within the infringement of Article 32 of the
GDPR, the punishable conduct attributed is limited to the
failure to adopt the most essential organizational
and technical measures to protect the security
of the platform in general, given the
vulnerabilities and deficiencies that were
revealed during the investigation. Within the scope of
the infringement of Article 32 of the GDPR, liability is not attributed
for the measures that affected the
breach of the duty of confidentiality (lack of encryption
of personal data), but only for the other
recognized deficiencies that affect other aspects of
personal data security and are independent of
the personal data breach that occurred (lack of
platform updates, internet access, lack of
monitoring and traceability measures, lack of risk analysis, lack of breach management and detection protocols…
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 74/173
etc).
Secondly, even if—as the respondent points out—it could be considered that there is a “concurrence of offenses” because
a single act is classified as an infraction in two
different provisions, the Principles of
specificity, subsidiarity, or concurrence would still not apply, since in this case
the alleged administrative infractions do not protect the same
legal interest. This is a requirement for applying any
of these principles, according to paragraph 30 of Guidelines 04/22:
“The principle of specialty, subsidiarity, or concurrence, which is often applied when the provisions protect the same
legal interest. In such cases, it would be unlawful to sanction the
offender twice for the same offense.”
Contrary to what the respondent argues, the
principle of specialty, subsidiarity, and concurrence cannot be applied (there is no
medial concurrence of infractions) because the legal interests
protected by the alleged articles are different. While
Article 5.1.f) of the GDPR aims to guarantee the
confidentiality and integrity of personal data, Article
32 of the GDPR aims to adopt and implement measures to
ensure a level of security appropriate to the risk. Therefore, in
the first case, the protected legal interest is the confidentiality and
integrity of personal data, while in the second, it is
the security of the processing.
The independence of both provisions—and therefore, the possibility of
committing two separate infringements—is deduced from
the very configuration that the EU legislator has given to
both types of infringements:
First, they are included in two different provisions, 5.1.f) and
32 of the GDPR, which protect different legal interests,
as already mentioned.
The GDPR establishes a classification of the infringement, while the LOPDGDD establishes a different classification for the purposes of the statute of limitations:
While the infringement of Article 5.1.f) of the GDPR is classified in Article 83.5.a) of the GDPR and classified for the purposes of the statute of limitations in Article 72.1.a) of the LOPDGDD; while the infringement of Article 32 of the GDPR is classified in Article 83.4.a) of the GDPR and classified for the purposes of the statute of limitations in Article 73.f) of the LOPDGDD.
28001 – Madrid 6 sedeagpd.gob.es 75/173
The maximum limits for the fines stipulated in Article 83.4 and 5
of the GDPR are different (10 million euros, or in the case of a
enterprise, an amount equivalent to a maximum of 2% of the
total global annual turnover of the
previous financial year, or 20 million euros or 4% respectively).
Similarly, the infringement of Article 5.1.f) of the GDPR has a three-year statute of limitations (very serious for the purposes of the statute of limitations),
while the infringement of Article 32
of the GDPR has a two-year statute of limitations (serious for the purposes of the statute of limitations).
Even the way to comply with each obligation is
configured differently: The purpose of Article 5.1.f)
of the GDPR is achieved through appropriate technical and
organizational measures of all kinds, while Article
32 of the GDPR focuses solely on technical and
organizational security measures.
Furthermore, it should be noted that breaching both provisions simultaneously is possible and something foreseen by the EU legislator, without
a breach of one preventing a breach of the other, and without
a breach of one requiring a breach of the other.
As paragraph 34 of EDPB Guidelines 04/22 states:
“34. When, however, two provisions pursue independent objectives, this constitutes a differentiating factor that justifies imposing separate fines. For example, if an infringement of one provision automatically leads to an infringement of the other, but the reverse is not true, these infringements pursue independent objectives.
There is no doubt that both rules pursue independent objectives in the present case, since an infringement of Article 5.1(f) is not always due to a failure to adopt one of the security measures referred to in Article 32 of the GDPR. And vice versa. Thus:
• An infringement of Article 5.1(f) of the GDPR can occur without implying an infringement of Article 32 of the GDPR. This is the case, for example, of a manager or administrator of a company who decides to disclose personal data in their possession as a result of carrying out their duties.” its functions and that does not
imply that there are no security measures or that they have
been breached.
An infringement of Article 32 of the
28001 – Madrid 6 sedeagpd.gob.es 76/173
GDPR can also occur without violating Article 5.1.f) of the GDPR when
the infringement is limited to the absence or breach of
security measures, since there is no evidence that the personal data
could have been, for example, accessed by an
unauthorized third party.
There is no medial concurrence of infringements, but rather a situation of
actual concurrence of infringements or plurality of actions, which justifies the
imputation of both infringements and the sanction for each of them.
Therefore, we are not dealing with a violation of the principle of ne bis in idem,
because, as the jurisprudence cited by the
respondent itself indicates (Judgment of the National Court of 23 of
July 2021 (rec. 1/2017): “(…) for there to be talk of “bis in idem” (double jeopardy), there must be a triple identity between the terms
being compared: objective (same facts), subjective (against the same
subjects), and causal (for the same grounds or reason for punishment).”
This is deduced from Article 31 of the LRJSP (Law on the Legal Regime of the Public Sector), referring to the
concurrence of sanctions, which states that:
“Article 31. Concurrence of sanctions.
1. Acts that have already been sanctioned criminally or
administratively may not be sanctioned again in cases where there is identity
of the subject, act, and grounds.
2. When a body of the European Union has imposed a
sanction for the same acts, and provided that there is no
identity of subject and grounds, the competent body to resolve the matter must take it into account for the purpose of determining the sanction that,
if applicable, it must impose, and may to reduce it, without prejudice to
declaring the commission of the infraction.”
From all of the above, it can be concluded that in the present case,
the principle of ne bis in idem is not violated, nor can the rule of Article
29 of the LRJSP be applied, since there is no identity of fact or
cause. We are not dealing with a single action with
a concurrence of offenses or administrative infractions (medial
concurrence of infractions), but rather with a plurality of actions
(real concurrence of infractions), insofar as
two different infringing conducts have been committed that have given rise to the
violation of two different protected legal interests, in which
case, there is no doubt that two independent
administrative infractions must be imputed and sanctioned.
28001 – Madrid 6 sedeagpd.gob.es 77/173
It should also be noted that the Supreme Court Order cited
by the respondent only admits The appeal in cassation is being processed.
The appeal filed in the aforementioned case is currently pending resolution.
SECOND. – ABSENCE OF CULPABILITY OR GROSS NEGLIGENCE
REGARDING THE INFRINGEMENTS CONTEMPLATED IN ARTICLES 5.1.F) AND 32 OF THE GDPR.
In this argument, the defendant maintains, primarily and in summary,
that it has not been proven that the cyber-attacker's unauthorized access to the data was due to the defendant's negligence, and that the defendant's culpability requirement is not met,
since the defendant was the victim of a cyber-attack.
This main argument is considered resolved, and the appeal is partially upheld.
The initial ruling is corrected, as it is acknowledged that the platform was the target of a cyber-attack, but it has not been proven that the cyber-attacker managed to access the platform and extract data. the
personal data contained in the aforementioned table ***TABLE.1 due to
negligent actions by the defendant. Since the lack of traceability and monitoring measures for the platform prevented verification of the
entry vector of the cyberattack, it cannot be determined whether these were
due to the platform vulnerabilities noted by the
inspector in his report of November 2, 2023.
However, as also explained, the defendant's culpability can be maintained with respect to the possibility that the personal data may be
published or transferred to third parties, given that it has been proven that the
pseudonymization and encryption measures for the personal data were not applied
that would have rendered them unintelligible to those
without the decryption key. Such encryption would not have prevented the
cyberattack but would have prevented the breach of the confidentiality of the
personal data. contained the platform, and would have prevented its
subsequent publication and transfer to third parties, since it is proven that it
put them up for sale on the dark web, and provided the inspector with a sample in which
no data was masked, and all personal data appeared
clearly visible and identifiable.
Furthermore, other arguments made by the respondent in
this allegation can be dismissed, since: (i) it has been considered that no special category data or data of minors is being processed, as will be explained later; (ii) and the
security breaches whose proceedings have been archived by this
Agency do not correspond to the same scenario and circumstances as the one
being judged here.
THIRD. - LACK OF EVIDENCE THAT THE MEASURES ARE
INEFFECTIVE.
28001 – Madrid 6 sedeagpd.gob.es 78/173
The respondent repeats the arguments already stated above, when
it indicates in this allegation that it should be applied The presumption of innocence, and the
"In dubio pro reo" principle, given the serious doubts that the measures
adopted by CECOTEC were ineffective and that the database targeted by the
cyberattack was indeed CECOTEC's. Since the administration is applying
strict liability that does not exist, given that the initial agreement is
based on indicators such as the number of platform users, and considering the
evidence presented, reasonable doubts exist.
It is understood that these arguments have already been addressed in the
previous allegation, and strict liability does not apply in this
case, since the reasons why it is understood
that gross negligence occurred with respect to the commission of the infringements
alleged in this proceeding have already been explained. Furthermore, when analyzing the
contested fact of the defendant's culpability in committing the infringement
of Article 5.1.f) of the GDPR, the principle of "In dubio pro reo" has been applied because
the entry vector was not established in the proceeding, and
the data breach or unauthorized access by the cyber-attacker was not attributed to the
defendant's negligence. Moreover, there is evidence, acknowledged by
the company's own cybersecurity director and DPO, of the occurrence
of the other alleged infringements.
FOURTH. - NON-EXISTENCE OF THE INFRINGEMENT OF ART. 33 GDPR REGARDING NOTIFICATION OUTSIDE THE 72-HOUR DEADLINE
The arguments put forward on this matter revolve around two
controversial issues, which should be analyzed separately. First, it is argued
that the starting date for calculating the deadline is arbitrary, and second, that there is no
infringement because there was no obligation to notify the breach.
First, CECOTEC considers that the starting date for calculating the
deadline (the "ad quo" date) that the Spanish Data Protection Agency (AEPD) took into account to calculate the start of the
72-hour period, that is, April 17, 2023, is entirely arbitrary, since
at that time, CECOTEC was not in a position to, or
had actual "knowledge" that a data breach had occurred.
Specifically, it states the following:
“(…) This party considers that the calculation of the starting date that the Spanish Data Protection Agency (AEPD) has taken into account to calculate the beginning of the 72-hour period,
that is, April 17, 2023, is entirely arbitrary, since at that
time, CECOTEC was not in a position or had any
actual “knowledge” that a data breach had occurred,
because the information from INCIBE (National Cybersecurity Institute) indicated that it could not
guarantee that the information was truthful, and furthermore,
it has only been proven that there were 6 real subjects at the time of
notifying the breach, and even today this remains the same, despite
any conjectures and suspicions that the investigating officer may have.”
28001 – Madrid 6 sedeagpd.gob.es 79/173
First, it should be clarified that CECOTEC does not expressly state in its
allegations from which date it believes the calculation of
this period should have begun, and furthermore, it is mistaken in stating that the commencement agreement started on
April 17, 2023, since the commencement agreement specified that the period was calculated
in hours and not in business days, and that had it been calculated in days,
the public holiday in the municipality where CECOTEC has its
registered office would not have been excluded, and the period would have ended on April 17, 2023. Therefore, with April 17, 2023,
the commencement agreement referred to the dies ad quem, or end of the period, and not the dies ad quo, or beginning of the period. This end date had also been calculated
taking into account the most favorable option for the responsible company.
To establish the initial and final dates for calculating the time period, we must start with the chronology
set forth in the fourth proven fact of this proposal, according to which:
The first notification of the cybersecurity incident issued by INCIBE
was received on the same day as the cyberattack (April 5, 2023), containing all the
information available to INCIBE, and was received in CECOTEC's
general inbox, but was not immediately forwarded to the
Data Protection Officer (DPO) or the Cybersecurity Director, remaining "in queue" to be answered
in order of seniority.
The company did not notice the sending of this alert email
until INCIBE sent a second notification email on
April 12, 2023, which was forwarded via the general inbox to CECOTEC's
Cybersecurity Director.
On April 13, 2023, the cybersecurity director requested that INCIBE
send him information regarding the incident. INCIBE responded on the same day, April 13, 2023, at 5:23 p.m., providing the
same information that was already included in the initial email of April 5, 2023.
It was then that the cybersecurity department began its
investigations into its systems and databases to
determine if a breach had occurred.
On April 13, 2023, the cybersecurity director carried out the relevant checks and concluded his investigation,
informing INCIBE on the same day, April 13, 2023, at 5:26 p.m.
that the 17 records in the sample matched the contents of a former CECOTEC platform that was shut down in 2021.
On April 14, 2023, at 2:31 p.m., the cybersecurity manager sent an email to the Data Protection Officer (Annex 7)
informing them of all emails exchanged by INCIBE,
the analyses performed, their conclusions, and referring both to the fact that the records matched those included in Table 1 of the former platform, and to the vulnerabilities and deficiencies that
were revealed in Legal Basis VIII and the eighth proven fact of this Proposal. Informing him of the results
of his investigations, he determines that he cannot scientifically verify
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 80/173
the extent of the breach because he does not have all the
records that the cyberattacker claims to possess.
The cybersecurity director verifies that the INCIBE email is not
a phishing attempt, and INCIBE replies on 17/04/23.
Finally, CECOTEC notifies this AEPD of the breach on 19/04/23
at 18:19 hours.
To determine when the initial day of the time limit for notifying this authority of the breach began, we must refer to Guidelines 9/2022, on the notification of personal data breaches under the GDPR, which state the following:
“2. When does a controller ‘become aware’ of a breach?
31. As explained above, the GDPR stipulates that, in the event of a breach, the controller shall notify the relevant authority without undue delay and, where feasible, no later than 72 hours after becoming aware of it. This may raise the question of when a controller can be considered to have ‘become aware’ of a breach. The EDPB believes that a controller should be considered to have ‘become aware’ of a breach when it has a reasonable degree of certainty that a security incident involving personal data has occurred.
32. However, as stated above, the GDPR requires the controller to take all necessary measures to ensure that the breach is carried out in accordance with the law.” appropriate organizational and technical safeguards
to determine immediately whether a breach has occurred and to inform the supervisory authority and the data subjects without delay. It also indicates that it must be verified that the notification was made without undue delay, taking into account, in particular, the nature and severity of the breach and its adverse consequences and effects on the data subject.24
This obliges the controller to ensure that it will be made aware of any breach promptly so that it can take appropriate action.
33. The exact moment when a controller can be considered to have become aware of a specific breach will depend on the circumstances of that breach. In some cases, it will be relatively clear from the outset that a breach has occurred, while in others it may take some time to establish whether personal data have been compromised. However, it is essential to emphasize the need to act quickly to investigate an incident in order to determine whether the security of personal data has indeed been breached and, if so, to take appropriate measures.
corrective measures and, if necessary, notify the relevant authorities.
34. After being informed of a possible breach by a person,
a media outlet, or another source, or when the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 81/173
data controller has detected a security incident,
the controller may initiate a brief investigation to determine whether
a breach has occurred.During this investigation period, the controller cannot be considered to have "awareness." However, the initial investigation should be expected to begin as soon as possible and establish with a reasonable degree of certainty whether a breach has occurred; a more detailed investigation may then be carried out. (...)
40. It should therefore be clear that the controller is obliged to act upon any initial alert and to determine whether or not a breach has occurred. This brief period allows for some investigations to be carried out and for the controller to gather evidence and other relevant details. However, once the controller has established with a reasonable degree of certainty that a breach has occurred, if the conditions of Article 33(1) of the GDPR are met, the controller must notify the supervisory authorities without undue delay and, where possible, within a maximum of 72 hours. If a data controller fails to act promptly and it becomes clear that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR.
* ...
*
*
*
*
*
*
*
*
* Applying these guidelines to the present case, it is established that
two initial alerts were received from INCIBE, but in this case, the
time limit for notifying the breach could not be calculated from the receipt of these alerts,
since, according to the EDPB, in order to confirm that the data
held by the malicious actor belonged to a CECOTEC database, it is understood that a brief preliminary investigation was necessary in this case.
During this investigation, the time limit for notifying the
breach could not begin, as the EDPB points out.
However, as the EDPB also indicates, the investigation should have been carried out
without undue delay and lasted only as long as strictly necessary to
obtain a “reasonable degree of certainty of the breach.” That is, it was sufficient to
conduct an initial investigation, limited to verifying whether the 17
records included in the advertisement sample were present in any of
its databases and how much personal data had been affected, without
needing to verify with absolute certainty that the malicious actor possessed
the personal data. of nearly a million people, ordered by the mobile phone number they claimed to possess.
All of this was because the important thing was to initiate, as soon as possible, the mechanisms
to mitigate the effects of the breach, and to continue the
investigation until more information was available, as these
Guidelines also indicate. It was not necessary to delay the investigation until it was known with certainty
28001 – Madrid 6 sedeagpd.gob.es 82/173
that the cyberattack had affected all the records that the
malicious actor claimed to have at their disposal.
In other words, to be aware of the breach and for the
duty to notify to arise, it is necessary to be certain that the breach has occurred,
but not about its nature (entry vector) or its scope (number of
data extracted), as the company's own "Security Incident Management Protocol of 22-4-21" stated (emphasis added):
or "Obligation to report any event security breach affecting
the confidentiality, integrity, or availability of personal data.
Any employee of the organization who becomes aware
of any indication of a security event or incident related to
personal data protection, through any of the
means indicated in section 2.1 of this document (regarding the
sources for identifying a security breach), must
report it within a maximum of 24 hours to the Data Protection Officer
and their immediate supervisor and departmental superior.
Or, the process of notifying the supervisory authority. When the
data controller becomes aware that a personal data security breach has occurred,
they must, without delay and no later than 72 hours after becoming
conscious of it, notify the Supervisory Authority.
A security breach is considered to have occurred when there is certainty that it has happened and
there is sufficient knowledge of its nature and scope.
... To determine whether CECOTEC acted with due diligence in fulfilling its
duty to notify the breach, two periods must be distinguished: (i) an initial
investigation period, during which it cannot be considered
that the responsible party had knowledge of the breach, and which will last until
it can be determined that there was “a reasonable degree of certainty of the
breach”; (ii) and a subsequent period, which begins from the date on which
CECOTEC became aware of that reasonable degree of certainty of the
breach, which is the true starting point from which the
72-hour notification period must be calculated.
A) Date CECOTEC's investigation began.
It is understood that, after receiving two alerts from INCIBE on April 5 and 12, 2023,
CECOTEC did not initiate the necessary investigations to verify
the existence of the breach until April 13, 2023, as acknowledged
by CECOTEC's Data Protection Officer in the initial response document provided (Resp#1):
28001 – Madrid 6 sedeagpd.gob.es 83/173
“Having received no response from us, on April 12, 2023,
we received a new email from INCIBE at the same address indicated
previously, requesting a report on the follow-up of the
incident, without providing any further details. Since we were unaware
of the first email sent, and this latest email from INCIBE
provided no information about the incident, CECOTEC replied
that same day requesting information about it, and it wasn't until
Thursday, April 13, that we received any further information.” In 2023, INCIBE provided all the information
regarding the potential breach, and therefore, CECOTEC became
truly aware of this alleged threat.
It was at that same moment that the Head of Cybersecurity,
together with CECOTEC's IT Department, began to
manage this alleged security breach by carrying out the necessary work and
technical verifications to try to confirm as quickly as possible that the information provided by INCIBE
did indeed affect CECOTEC.
It has been established that there was an undue delay in the duty to initiate
the relevant investigations to verify the existence of the breach, which
was attributable to the following actions of the defendant company, since
:
(i) It has been established that the first notification email of April 5, 2023
was received in CECOTEC's general mailbox but that said first email was not forwarded
with the priority that an alert of this nature deserved, to the individuals responsible for managing the
breach. This is expressly acknowledged by the DPO report
submitted, and corroborated by the initial response to the
request for investigation, which states the following:
“As explained in the report submitted by the Data Protection Officer
in the breach notification, on April 5,
2023, we received an email from INCIBE at
our general email address ***EMAIL.1 informing us
of a possible cybersecurity incident with the reference
code [INCIBE-CERT 3713032]. This notification was not addressed
in a timely manner by this entity, as emails
received in this mailbox (which is intended for
clients) are addressed in order of age. Furthermore, that
week there were other emails to address,
considering that April 7 and 10 were holidays and
the email that the DPO sent to those in charge of
this general mailbox in which inquired about what had happened and warned them
of the need to forward this type of communication
to the Data Protection Officer (DPO) and the Director of Cybersecurity, which is attached
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 84/173
as Annex 7 of Response #1.”
(i) Secondly, when the second alert email was received on April 12,
2023, the Director of Cybersecurity wasted another day
obtaining the initial information contained in the first email of
April 5, 2023. INCIBE responded on April 13, sending
the same information contained in the original email.
The subject line of the email dated April 12, 2023, was “Possible cybersecurity incident,” and its text clearly stated that it was
a follow-up email to the first email sent, and included the
incident code, which could have been used to retrieve it
from CECOTEC's main inbox.
Therefore, instead of retrieving it from the main inbox,
CECOTEC delayed checking for the breach for another day,
acknowledging that “we were unaware of the first email sent.”
From the above, it can be deduced that the defendant did not act with due diligence
by initiating the investigation period on April 13, 2023, at
11:12 a.m., when it received the third email from INCIBE, with the information already
sent on April 5, 2023.
B) Regarding the date from which CECOTEC became aware of the
breach.
Within this investigation period initiated to verify the reasonable or sufficient certainty of the breach, it has been found that several verification actions were omitted and unnecessary requests for information were made, demonstrating a lack of diligence on the part of those responsible for detecting the breach, since:
In both INCIBE alert emails of April 5 and 12, it was stated
that to obtain more information, the malicious actor could be contacted
on the forum, providing the link to the advertisement and including
all the necessary information. This information was
used to conduct a proper investigation by the inspector of
this procedure, who was able to contact the actor without major difficulties on August 4, 2023, and obtain a sample of more than 1,000 records,
which has allowed verification that many more people were affected by the breach (at least 933).
However, despite having the contact information from the first
alert email, neither the cybersecurity director in his email of April 14,
2023, nor the DPO in his reports have stated that they
28001 – Madrid 6 sedeagpd.gob.es 85/173
attempted to contact the malicious actor. They even try to impute
responsibility to this agency in their second statement of objections to the
initiation agreement, for not having provided them with the contact information,
when it was available to them from the first alert, which was
forwarded to them again by INCIBE on April 13, 2023.
Therefore, the claim that CECOTEC did not have
“actual knowledge” of the breach cannot be accepted, simply because INCIBE
indicated that it could not guarantee that the information published by the
malicious actor was truthful, given that the data controller is the only one who can verify the plausibility of the cyber-
attack, comparing the records with the contents of its database.
Furthermore, it is on record that INCIBE provided him with all the data on the malicious actor that would have allowed him to
carry out these checks himself, starting on April 5th.
For this same reason, the allegations made
in his second statement of objections to the initial agreement are also inadmissible,
when CECOTEC states that this agency knew the data on the malicious actor
but did not share it with CECOTEC, and that had it
known it, it could have reported the incident earlier. Given that
CECOTEC had the same data available to it as the inspector
from the beginning, and failed to use it to fulfill its essential duty
to promptly carry out the necessary checks to detect the
reality and scope of the breach.
On the other hand, it is on record that the cybersecurity officer carried out the
appropriate checks on April 13, 2023,
requiring less than half a day to complete them. This demonstrates that, had the protocol been functioning correctly, the alert would have been detected on April 5,
2023, and its validity could have been confirmed on April 6, at which point the 72-hour period for
notifying it would have begun.
However, although the investigation period itself was brief, the
conclusions reached and the information provided demonstrate
a complete lack of understanding of the concept of a breach, its
detection, and the obligation to report it. In reporting the results of these
checks, the cybersecurity officer sent an email
to INCIBE on April 13 at 5:26 p.m. that does not match
what was reported to their Data Protection Officer (DPO) in the email of April 14, 2024,
concluding that although all the records in the
sample were included in the aforementioned table ***TABLE.1 of the
old platform, they could not determine "with certainty" that a
cyber-attack had occurred because they only had 17 records,
28001 – Madrid 6 sedeagpd.gob.es 86/173
having requested additional information from INCIBE to carry out this
check.
The wording of the email sent to INCIBE does not imply at any point
that they requested additional information from INCIBE, nor that they were waiting to receive more information.
But in any case, it must be said that the request for
additional information could not justify the delay in this investigation period, since: (i) it has already been stated that the initial investigation
does not require this degree of absolute certainty or “with absolute certainty,” so
not knowing more information was not a sufficient excuse to wait
for INCIBE to reply again, and to further delay the notification period; (ii) and the person in charge should have realized that INCIBE had already
stated in all its emails that it could not guarantee the
veracity of the information and did not have any further information, indicating how
this additional information could be obtained;
Thus, on April 14, 2023 (Page 110 of the file), an
email was sent from ***EMAIL.3 to dpd@cecotec.es, in which, in addition to
providing further details regarding the platform's deficiencies that had
prevented it from detecting the attack vector, it was indicated that it was
waiting for INCIBE to reply to the email sent the previous day
at 5:26 PM, which, as we have seen, did not request any
information.
However, the email sent on April 13, 2023, at 5:26 PM
to INCIBE does not request any additional information nor does it report these
vulnerabilities: “The data shown in the image provided
by user ***USER.1 in ***FORUM.1 is test data.
Furthermore, the website with said data was shut down in 2021 and is no longer
operational. For now, we cannot determine whether it
constitutes a breach based solely on the image shown.
The reference being discussed is [***REFERENCE.1].
In any case, we are at your disposal for anything you need.”
It has therefore been established that CECOTEC did not apply its own
2021 Incident Management Protocol (which regulated how to detect
a security incident and report a breach), and communication of this protocol to
employees and managers prior to the breach is not
documented. As stated in the file:
That those in charge of the CECOTEC general mailbox did not forward
the first
cybersecurity incident alert to those responsible for detecting and reporting the breach.
The 2021 Protocol does not
contain the contact information for the individuals to whom this
28001 – Madrid 6 sedeagpd.gob.es 87/173
communication should have been sent.
That both the cybersecurity manager and the Data Protection Officer of the
company were unaware that their Protocol stated that it was not
necessary to know with certainty the entry vector of the
cyberattack or whether it had affected all
records in the database. Since they point out that the
notification was made proactively, and despite not being obligated to do so,
because the cyberattack was not considered credible, since the
cybersecurity officer had not been able to determine
with certainty
It has also been demonstrated that corrective measures were adopted
after the incident to prevent these delays from recurring: (i) since Annex 7 of document Resp#1 shows that the
Data Protection Officer sent an email on April 15, 2023, to CECOTEC
and INCIBE staff informing them of the email addresses to which
these alerts should be sent, (ii) and a new Security Breach Management Protocol
was developed on August 29, 2023, which is provided
in Resp#2.
Had an appropriate breach detection and management protocol been applied,
the verification actions that should have constituted the
brief initial investigation period referred to in EDPB Guidelines
9/22 should have begun on April 5, 2023, when
the first alert was received. And since the respondent acknowledged that it
noticed it had received the second alert, there is no doubt that,
at the very least, they should have begun on April 12, 2023, when
the second reminder was received, without having to wait until April 13,
2023, given that CECOTEC could retrieve the initial email from its inbox
and obtain all the necessary information to initiate said investigation.
However, the undue delay in initiating the
investigations proves that the respondent did not have the appropriate
measures for detecting, preventing, and mitigating the effects of
potential breaches of this platform. But it does not affect the calculation of the
period imputed as a breach of Article 33 of the GDPR, which
begins when the data protection authority had a reasonable degree of certainty that
the breach had occurred.
Consequently, the proceedings show that the date from which CECOTEC can be considered to have been aware that there was a reasonable degree of certainty of the breach, having verified that it had affected at least six real people, was April 13, 2023, at 5:26 p.m., as stated by the Data Protection Officer in its report:
28001 – Madrid 6 sedeagpd.gob.es 88/173
Therefore, the initial period (dies ad quo) for notifying this agency of the breach must be calculated from April 13, 2024, at 5:26 p.m., applying the rules for calculating time limits provided for in the European regulation referenced in the initiation agreement (Regulation
EEC, EURATOM No. 1182/71, of June 3, 1971), which will be referenced in the grounds. of Law XI of this proposed resolution.
Since the Data Protection Officer (DPO) is the competent body to report on when the obligation to notify arises, the DPO of
CECOTEC has expressly acknowledged that this decision to notify the breach occurred on
April 14, 2024, when the email from the cybersecurity department was sent to them informing them of the investigation carried out, stating that the
delay within the 72-hour period was due to the existence of several
public holidays. Notwithstanding that these days are not considered holidays,
when the deadline is calculated in hours, for the reasons that will be analyzed in
legal basis IX, it is clear that it has been
acknowledged that CECOTEC was aware of the breach and decided
to notify it on the aforementioned 14th.
Having confirmed the negligent conduct, it should be noted that, in accordance with the provisions of
Article 33 of the GDPR, interpreted by the aforementioned Guidelines,
the interpretation most
favorable to the accused should be applied, considering that the deadline for the commencement of the duty to
notify the breach did not begin on April 12, 2024, after receiving the second
alert from INCIBE—as indicated in the initial agreement—but rather began on April 14,
2024, at 2:31 p.m., when the cybersecurity officer
informed the Data Protection Officer (DPO), who then decided that it was appropriate to notify the breach,
more than 72 hours elapsed until it was finally notified on the 19th. April 2023
- Once the issue of the deadline is clarified, the
allegations on which CECOTEC argues there was no
obligation to notify the breach, and yet CECOTEC decided to do so
proactively, should also be dismissed.
Specifically, CECOTEC maintains that it is not mandatory to notify all
personal data breaches, given that the GDPR provides an exception to this
obligation when the controller can guarantee that the
personal data breach is unlikely to pose a risk. Therefore, considering
the type of data affected, already mentioned, which did not
include identifying data such as names and surnames, and with only 6 real people initially affected,
it is understood that the
existence of a risk was unlikely. They maintain that: “in this regard, it is appropriate to consider the
criteria of the former Article 29 Working Party, which, in Guidelines
WP250, determines when a breach is likely to pose a risk.”
28001 – Madrid 6 sedeagpd.gob.es 89/173
First, it should be noted that the aforementioned Guidelines WP250 of Working Party 29
on the notification of personal data breaches
in accordance with Regulation 2016/679 refer to the
risk factor as the trigger for notification and its exceptions,
distinguishing the duty to notify the data protection authorities from the
duty to inform data subjects, which have a different risk assessment threshold, expressly stating the following:
“Although the GDPR introduces the obligation to notify a breach, it is not
mandatory in all circumstances:
• Notification to the competent supervisory authority is mandatory
unless a breach is unlikely to pose a risk to
the rights and freedoms of individuals.
• Notification of a breach to the individual should only take place
where it is likely to pose a high risk to their rights and
freedoms.
(…) As As explained previously, notification of a
breach is mandatory unless it is unlikely to pose a
risk to the rights and freedoms of individuals, and the
key factor requiring notification of a breach to data subjects is
when it is likely to pose a high risk to the rights and
freedoms of individuals. This risk exists when the breach could
result in physical, material, or non-material harm to the
individuals whose data has been breached. Examples of such harm include discrimination, identity theft or fraud,
financial loss, and reputational damage (...)”
Therefore, to apply the exception to the duty to notify this
agency of the breach, it would be necessary that the breach be unlikely to pose a
risk to the rights and freedoms of individuals. It is irrelevant whether the
risk is high, medium, or low, and certainty of that
risk is not required, only a mere probability.
In the present case, there is no doubt that there is a probability that
the breach constitutes a risk to the rights and freedoms of the individuals
whose data was included in table ***TABLE.1, given that:
The defendant verified that all the records
in the sample (17 records) were included in the aforementioned table,
even matching the customer identifier codes, which are automatically generated
by the database, and that the platform on which they were
located was outdated, with internet access in its
SERVICE.1 and suffered from multiple vulnerabilities that could
hypothetically be the entry point. While there was no certainty that
28001 – Madrid 6 sedeagpd.gob.es 90/173
these were the entry point, nor that the malicious actor had
records corresponding to almost 1 million people, there was a
probability that this was the case.
And furthermore, there is no doubt that there was a risk that the cyber
attacker, or the people to whom they might transfer the data whose
sale had been offered since April 5, 2023, would use the allegedly stolen
personal data to commit crimes of
identity theft, fraud, financial loss, etc., which the W250 Guidelines classify
as a clear risk scenario.
And this holds true even though it is true that the sample of 17 records
contained in the advertisement did not publish the names and surnames, masking
them as INCIBE indicated, because the data was not
encrypted, given that the cyber attacker had access to them and
provided them in full to the inspector when handing over the second sample of
1,000 records. The defendant should also have understood that it was highly
probable that the cyber attacker had access to the content of said data,
even though they had not published it, given that the fields appeared in the
sample. Furthermore, they already had sufficient identifying data, such as
the ID number, address, or telephone number of the account holders, which would have
enabled them to commit these identity thefts or frauds without
needing to have the names and surnames.
This interpretation is confirmed by Guidelines 1/2021 on examples
of notification of personal data breaches
adopted on December 14, 2021, by the EDPB, which dispel any
doubts regarding the concurrent risk in cases of “Stolen material
containing unencrypted personal data,” analyzed as CASE NO.
11, stating that: “During the risk assessment, the controller
must take into account the possible consequences and
adverse effects of the breach of confidentiality. As a result of the
security breach, the affected data subjects may suffer identity
theft by using the data available on the stolen device,
and therefore the risk is considered high.”
Furthermore, in case of doubt, Guidelines W250 clearly state that the data controller must err on the side of caution and notify:
Therefore, when assessing the risk that a breach may entail, the data controller must take into account a combination of the severity of the potential impact on the rights and freedoms of individuals and the likelihood of its occurrence.
Clearly, when the consequences of a breach are more serious, the risk is higher, and likewise, when the likelihood of it occurring is greater, the risk also increases.
28001 – Madrid 6 sedeagpd.gob.es 91/173
occurring is higher. In case of doubt, the data controller must err on the side of caution and notify.
In conclusion, it follows from the above that there was a duty to notify the
breach and, therefore, this notification should have been made within the maximum period of 72 hours
from the time CECOTEC had a reasonable degree of certainty that the
cyberattack had affected its platform and the cyberattacker had at least
the 17 records that appeared in the advertisement.
FIFTH. - NON-EXISTENCE OF THE INFRINGEMENT OF ARTICLE 34 GDPR.
NOTIFICATION TO THE DATA SUBJECTS.
According to what is stated in the sixth finding of fact of this proposal, it is established
in the proceedings that the defendant did not notify the breach to the 6
affected parties included in the initial sample provided by the malicious actor's advertisement, and this Agency has also not been informed that the breach has been
notified to the 933 affected parties whose personal data is contained
in the second sample that was provided to the inspector in these proceedings.
In its allegations, the defendant states its intention not to disclose the
breach, persisting in its infringing conduct, even after learning
the detailed reasons why the initial agreement considered it
necessary and still necessary to disclose the breach to those affected.
Or, primarily, CECOTEC argues that there is no infringement since it has not
been proven that the personal data breach suffered by CECOTEC
entailed a “high risk” to the rights and freedoms of the
data subjects, with the consequent obligation to notify them, beyond
the subjective assessment carried out by the investigating officer, who, incidentally,
was appointed in said initial agreement, and whose duties began
at the start of the investigation.
Contrary to the respondent's assertion, the assessment
made in legal basis XII of the initial agreement is not considered
subjective. Rather, it was based on the evidence acknowledged by the respondent itself,
and thoroughly explained the reasons why the breach was deemed
to pose a high risk, and why none of the
exceptions to the duty to notify provided for in Article 34 applied.
Turning to the analysis of the disputed issue, Article 34 of the
GDPR states that "Where a personal data breach is likely to result in a high risk to the rights and freedoms of
natural persons," the controller shall communicate it to the data subjects without undue delay.
Again, the term "probability" is used; certainty is not required for
there to be a duty to communicate the breach to the affected parties. As the
respondent points out, the required risk threshold for notification of the breach has been raised, and a probability is now necessary. that the breach poses a
high risk.
28001 – Madrid 6 sedeagpd.gob.es 92/173
Regarding the reasons why the breach was considered not to
pose a high risk, the respondent states that:
“CECOTEC initiated the appropriate checks from the moment
it became aware of the INCIBE email and contacted
them by telephone, and although initially it had doubts about the
certainty of the breach, it was finally reported to the Supervisory Authority as it obtained information about it.
In this context, an internal assessment was carried out regarding the
"high risk" based on the objective information available at the time
the breach was discovered, based on the factors indicated in Guidelines 9/2022
on notification of personal data breaches under the
GDPR, dated March 28, 2023.
-Regarding the nature, sensitivity, and volume of the personal data:
The data consisted of incomplete contact information and was not of a special category.
-Regarding the volume of data:
Only six pieces of data belonging to real individuals were verified.
-Regarding the ease of identifying the individuals:
It was difficult, given that the names and surnames of the data subjects were not included, nor was there any associated documentation.
-Regarding the type of breach:
It affected the confidentiality of the data by an unauthorized third party, but not other aspects such as
availability and integrity.
- Regarding the severity of the consequences for individuals: It was
considered not to be serious given that the data is not of a special category,
identity theft is neither automatic nor simple since
the names and surnames of those affected are not recorded, nor is there
any evidence of identity theft.
- Regarding the characteristics of the individuals: They were not vulnerable subjects nor minors.
Following this internal assessment and in accordance with the results of the
COMUNICA BRECHA tool provided by the Spanish Data Protection Agency (AEPD), CECOTEC did not
deem it necessary to report the breach.
However, the respondent does not carry out an adequate assessment of the concurrent risk, since it does not take into account all the concurrent factors
to assess the concurrence of this risk, as referenced in the Article 29 Working Party Guidelines (WP29), which are not limited to assessing only the type of data, nor the number of affected individuals, as
the respondent indicates.
When assessing the risk factors for individuals arising from a breach of
personal data confidentiality, the data controller must
take into account the specific circumstances of the breach, including the
severity of the potential impact and the likelihood of its occurrence.
28001 – Madrid 6 sedeagpd.gob.es 93/173
Therefore, WP29 recommends that the assessment take into account the criteria
indicated by the respondent, such as the nature, the non-sensitive nature of the
personal data affected, and the volume of personal data affected that
the respondent was aware of at the time of notifying the breach.
But other factors also came into play. a series of factors that the guidelines identify
as influential in determining the presence of high risk, such as the
ease of identifying individuals, and the severity of the
consequences for those individuals.
Thus, on the one hand, the Guidelines state that: “An important factor to
consider is how easy it will be for a party with access to compromised
personal data to identify specific individuals, or to compare the
data with other information to identify those individuals. Depending on
the circumstances, identification might be possible directly from
the breached personal data without the need for a special
investigation to discover the individual's identity, or matching the
personal data with that of a particular individual might be extremely
difficult, but this would still be possible under certain conditions.
Identification would be possible directly or indirectly from the breached data, but it could also depend on the specific context of the
breach and public access to related personal data. This may be
more relevant for breaches of confidentiality and availability.”
Furthermore, the guidelines indicate that the
severity of the consequences for individuals must also be assessed, stating that: “The fact
that the data controller is aware that personal
data is in the hands of persons whose intentions are unknown or
are possibly malicious may influence the level of potential risk.
A breach of confidentiality may occur whereby personal
data is disclosed to a third party, as defined in Article 4, paragraph 10, or to another recipient in error.”
This risk factor is even more applicable in the present case,
where it has not been possible to identify the malicious actor, and the database
has been for sale on a dark web forum since April 5, 2023, as stipulated by
the aforementioned Guidelines, which state that: “The permanence of the consequences for individuals must also be taken into account when it is considered
that the impact is greater if the effects are long-term.
Therefore, the allegations made must be dismissed, since
it is considered that CECOTEC has not carried out an adequate assessment of
all the concurrent risk factors, as indicated in the W250 Guidelines of Working Party 29, erroneously concluding that there is no
probability that the security breach entailed a high risk, since
it did not take into account the factors related to the ease of
28001 – Madrid 6 sedeagpd.gob.es 94/173
identifying individuals affected and the severity of the damage that could occur
at the time the breach was detected,
affecting 6 real people.
There is no doubt, therefore, that on April 14, 2024, it became
aware that a breach had occurred that entailed a
high probability of risk for these 6 affected individuals. Therefore, the
defendant had the obligation to inform them of the breach, at a minimum,
these 6 individuals, as indicated in Article 34 of the GDPR. For this reason, on the
date of the initial agreement, an administrative infringement was charged and an initial penalty of €40,000 was imposed
for failing to inform the breach
these 6 individuals, whose data leak was known since the initial
investigations were carried out.
In light of the investigation carried out, there are grounds to reassess the
scope of those affected, and therefore the data controller must
reassess the probability of concurrent risk in light of the new
facts accredited during the investigation for the purposes set forth in the
aforementioned Guidelines W250 and Guidelines 9/22 on breach notification.
Thus, as stated in the third and fifth findings of fact, it has been
established during the investigation of the proceedings that the breach affected
more than 6 people, with the number of affected individuals amounting to at least 933
natural persons whose personal data was included in the sample that the
malicious actor provided to the inspector.
The initial agreement made it clear that the malicious actor had
provided this second sample with 1,000 records to the inspector, which
was forwarded to the defendant company when it requested a copy of the
file, with said list being delivered to it on April 30, 2024.
As recorded in the official record, this sample
contains the personal data of a total of 933 people with identified National Identity Documents (DNI).
The defendant had this sample of 1,000 records. since receiving
the copy of the file on April 30, 2024. And yet, there is no record
that the respondent expanded the initial investigation and carried out the
pertinent data verification and comparison, comparing said sample with
the data included in its database, as this investigating officer has done,
thereby failing to fulfill its duty to reassess this risk and evaluate whether it was appropriate
to communicate said information to all those affected.
And there is no doubt that the malicious actor obtained these 1000
records from table ***TABLE.1 of the respondent, because all
the records matched, including the 4 identifier codes that
can only be obtained by accessing the database.
Therefore, according to the evidence presented in the third and sixth proven facts, it can be understood that the total proven
28001 – Madrid 6 sedeagpd.gob.es 95/173
The number of individuals affected by the breach is 933, as shown in the sample and table provided by the complainant. The commission of the infringement of Article 34 of the GDPR must be confirmed, and an increase in the penalty to be imposed should be proposed.
This is because the initial agreement only considered a scope of 6 individuals, and it was demonstrated during the investigation that the number of those affected by the breach reached a minimum of 933.
Furthermore, CECOTEC also points out that the aim is to avoid the “unnecessary fatigue of notifications,” which it says is addressed in Guidelines
9/2022, on the notification of personal data breaches
under the GDPR. These guidelines state that the threshold for communicating the breach to individuals is higher than for notifying supervisory authorities.
It is true that the aforementioned Guidelines 09/22 state that “Therefore, the threshold for the Communication to individuals is higher than for
notification to supervisory authorities and, therefore, the
communication of all violations to individuals will not be required, thus protecting them from
an excess of notifications.” However, communication fatigue would
occur only in cases where there is no obligation to
notify the authority (because a risk of
violation of rights and freedoms is unlikely), and where there is no obligation to
communicate it to the affected parties (because there is no probability that the
breach entails a high risk), and yet the decision is made to make the notification
/communication despite it not being necessary.
In the present case, we reiterate, both the notification to this Agency and
the communication to the affected parties were a mandatory duty for the
controller, and not a discretionary power, so there is no communication fatigue.
Finally, CECOTEC points out that this agency has the corrective powers attributed to it by Article 34.4 of the GDPR, and based to the same
, should have instructed CECOTEC to proceed with the notification
of the breach to the interested parties, if it considered this mandatory, during
the preliminary actions phase or when forwarding the agreement to initiate
the present procedure. And it is stated that: “this party fails to understand
that this order has been issued in other proceedings before the
AEPD – as can be seen, among others, from the resolution dated February 17,
2022, issued in PS No. E/06660/2021 or in the preliminary investigation files
E/06214/2020 and E/06177/2020, and that in
the present procedure, the possibility of
offering said prior option to CECOTEC has been completely ignored, opting instead directly for the
initiation of this Agreement.”
28001 – Madrid 6 sedeagpd.gob.es 96/173
First, the Principle of proactive responsibility that underpins the
GDPR regulation implies that it is the responsibility of the data controller
to determine when this breach notification should occur,
and, as already stated, to notify this agency and inform the
affected parties if there is any doubt. This authority or any other body
is not obligated to advise them of this.
This assertion is surprising, given that the respondent has consistently maintained
from the initial communication within this case file
that there was no need to report the breach and continues to insist
on this point in its written submissions against the initial agreement, contrary
to the opinion of this Agency, which has expressed its views on this matter on several occasions.
During the preliminary investigation phase of the proceedings,
a report was requested explaining why the
breach had not been reported, and the respondent replied that it did not consider it necessary to report the
breach to these six individuals. Given this admission of the lack of
communication, it was understood that There was evidence of a violation of Article 34 of the GDPR, justifying the initiation agreement in a comprehensive manner as to why it was deemed necessary to impute said violation. Specifically, it dedicated legal basis XII to the breach of the duty under Article 34 of the GDPR, indicating in legal basis XV, within the corrective measures that the respondent should: “Demonstrate to this Agency within 15 working days that the respondent has notified the personal data breach to the affected parties whose data has been affected by the cyberattack, in accordance with the terms and conditions provided for in Article 34 of the GDPR.”
This corrective measure, incidentally, has not yet been implemented,
and it can be deduced from the allegations presented that the respondent has no
intention of doing so, as it does not consider it necessary.
Finally, regarding the allegation that: “The Spanish Data Protection Agency (AEPD) has not applied, to
this factual scenario, the same criteria it has used in other
resolutions, and this party is unaware of the legal reasoning that
underpins such a decision,” it should be noted that the grounds for initiating the
sanctioning procedure are exhaustive in this case, in which there was irrefutable
evidence of the lack of communication to the affected parties, which had been
acknowledged by the respondent, and which persists to this day. The allegations
made by the respondent (PS No. E/06660/2021 or in the preliminary investigation files E/06214/2020 and E/06177/2020)
refer to preliminary investigation files in which the inspector determined the need for
communication, but which did not end with the initiation of a sanctioning
procedure, but were closed due to a lack of evidence of
the commission of an infraction. Therefore, based on factual scenarios
completely different from the present one, and even though it is discretionary for the supervisory authority
to adopt corrective measures during the investigation phase, the
truth is that there is no comparative grievance whatsoever. Furthermore, it must be
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 97/173
considered that these are files processed in the years 2020 and 2021,
where the legal situation was different, given that the EDPB Guidelines 09/2022 on breach notification, which have been referenced, had not yet been issued.
From all of the above, it follows that the defendant's
allegations regarding the failure to communicate the breach to the affected parties must also be dismissed, since it has been proven that the defendant
should have communicated the breach to a total of 6 people when it became aware of it
on April 13, 2023, and extended said communication to a total of
933 people, once it received a copy of the file on April 30, 2023.
Having failed to comply with this obligation, the charge of infringement of Article 34 of the GDPR should be upheld, and a higher penalty than the one
initially imposed should be proposed, as will be set out in Legal Grounds XIV and XVI of this proposal.
SIXTH. - LACK OF PROPORTIONALITY IN THE IMPOSITION OF
SANCTIONS AND ABSENCE OF GRADUATING SEVERITY.
- Prior to this, CECOTEC informed the Spanish Data Protection Agency (AEPD) that the platform
‘***SOFTWARE.1’ was completely disabled, ceasing the processing of
data.
In this regard, it should be clarified that, although the disabling of internet access to
the platform is considered proven, having been verified
and documented by this investigating officer on June 3, 2024, no
proof is provided to justify that the
processing of personal data carried out by CECOTEC with respect to the
platform has actually ceased. This requires independent proof, since the
disabling of the platform does not imply that the
processing of personal data, which continues to be stored on the
platform of the respondent, has ceased until the respondent justifies that it has proceeded to
block and/or delete the data.
And, It should also be noted that disabling internet access to the
platform cannot act as an exemption or mitigation of
liability, since it was implemented even after
the initiation of this procedure had been agreed upon. It can only have the effect of not
including this disabling action among the possible corrective measures that may be
appropriate to order regarding the processing in accordance with Article
58 of the GDPR.
- And the same applies to the last statement made, regarding
"Finally, it is reported that the Company continues to improve, being
currently immersed in a GDPR compliance audit and in the
updating of risk analyses, carrying out DPIAs and verifying
security measures. And that it is willing to accept any
proposal for improvement."
28001 – Madrid 6 sedeagpd.gob.es 98/173
- Secondly, the allegations indicate that: "It has not been considered by the
AEPD, for now and without prejudice from the outcome of the investigation, no criteria
for grading the sanctions that could mitigate them,” listing
a series of factors that it believes should be considered
as such to reduce the sanction to be imposed, without providing any details or supporting
evidence to substantiate the claims made.
First, it should be noted that data protection regulations do not
contain a list of mitigating and aggravating circumstances as such, but rather
an enumeration of circumstances for grading the sanction, which,
in accordance with the Guidelines issued by the EDPB for calculating fines
(Guide to fines to which the respondent has previously referred),
established in Article 83.2 of the GDPR, can act as neutral, mitigating, or aggravating factors, depending on the
circumstances. This list is further expanded by the grading circumstances
contained in Article 76 of the LOPDGDD.
In general, it is observed that most of the circumstances mentioned by the
respondent in its allegations have not been foreseen as mitigating factors by the
European or national legislator, and therefore could not be considered as such
by this supervisory authority. It is important to remember that the public administrations
responsible for applying the rules are subject to the Principle of
legality, and are not granted the freedom to apply
mitigating or aggravating circumstances that are not expressly listed in the
applicable regulations, and have not been reliably proven.
Therefore, the application of mitigating circumstances or factors that reduce
the penalty for an infringement is only possible in the cases
legally defined in Articles 83.2 of the GDPR and 73 of the LOPDGDD, and
provided that their existence is proven, a mere
assertion not being sufficient.
In light of the proven facts, it is considered that the following mitigating factors alleged by the
respondent are not present in the
case at hand:
or “Due to the facts described in the Initiation Agreement, my client has not
obtained any benefit, remembering that this is an attack by an
unauthorized third party.”
This grading criterion is established in Article 76.2.c) of the
LOPDGDD in accordance with the provisions of Article 83.2.k) of the GDPR,
according to which administrative fines will be imposed taking into account
any “aggravating or mitigating factor applicable to the circumstances of the
case, such as the financial benefits obtained or losses avoided,
28001 – Madrid 6 sedeagpd.gob.es 99/173
directly or indirectly, through the infringement”, it being understood that
avoiding a loss has the same nature for these purposes as
obtaining benefits.
As the EDPB Fines Guide points out: “Article 83(2)(k) of the GDPR gives the supervisory authority leeway to take into account any other aggravating or mitigating factors applicable to the circumstances of the case, but as its literal text indicates, it contains aggravating and mitigating factors or circumstances.
Therefore, in this circumstance, the possibility remains open for the supervisory authority of each country to provide in its national legislation for other circumstances, including those related to the socio-economic context in which the controller or processor operates, those related to the legal context, and those related to the market context. That is, for them to be applicable, they must be provided for in national legislation, as is the case in Spain, where Article 76(2)(c) of the LOPDGDD refers to economic benefits, stating the following:
“2. In accordance with the provisions of Article 83(2)(k) of the Regulation (EU)
2016/679 may also take into account:
c) The benefits obtained as a consequence of committing the
infringement.”
With regard to the absence or obtaining of economic benefits from
the infringement, the matter is clear and leaves no room for doubt, since the Guide to
Fines clearly determines what case law has repeatedly
established in sanctioning law, which is the following:
“110. In particular, the economic benefit of the infringement could be an
aggravating circumstance if the case provides information on the
benefits obtained as a result of the GDPR infringement.”
Therefore, the application of this mitigating circumstance can be dismissed because
economic benefits can only operate as an aggravating circumstance when
it has been proven that the sanctioned party obtained them as a result of
committing the infringement, which is not the case here. Therefore, this aggravating circumstance has not been
applied when determining the sanction. It is not possible, as it is not provided for in the applicable regulations, for the absence of obtaining economic benefits to operate as a mitigating factor of liability. Moreover, this is not demonstrated by the claimant.
Thus, considering the absence of benefits as a mitigating factor would negate the
deterrent effect of the fine, insofar as it diminishes the impact of the
circumstances that actually influence its amount, granting
the responsible party a benefit they have not earned. It would be an
artificial reduction of the penalty that could lead to the understanding that violating the
28001 – Madrid 6 sedeagpd.gob.es 100/173
rule without obtaining benefits, financial or otherwise, will not
produce a negative effect proportional to the seriousness of the infraction.
or “There is no evidence of repeated conduct, prior offenses, or intent to
cause harm on the part of CECOTEC.”
First, it should be noted that the lack of a criminal record, which
we assume refers to prior criminal records or administrative proceedings
brought against the same party, is not considered a
mitigating or aggravating circumstance, and has not been taken into account
in determining the appropriate sanction.
Second, intent is not considered a mitigating circumstance but rather
is a factor in determining the appropriate sanction, as outlined in
Article 83.2.b) of the GDPR. This was assessed in the initial agreement when
determining the sanction for each of the alleged infringements, where
the degree of negligence deemed to have been committed was clearly established,
and will be done again in this proposal. Therefore, it is being considered that the infringements were committed through negligence and not intentionally, in which case the penalty would be much higher, given that the legal limits for each of them can reach 2% or 4% of the company's turnover.
Finally, the repeated nature of the conduct only acts as an aggravating circumstance when the requirements set forth in Article 83(2)(e) of the GDPR are met. These requirements are also considered aggravating circumstances, which have not been applied in this case. This article refers to: “any prior relevant infringement committed by the controller or processor.”
Finally, the repeated nature of the conduct only acts as an aggravating circumstance when the requirements set forth in Article 83(2)(e) of the GDPR are met. The aggravating nature of recidivism is inherent to its very nature, without it being possible to understand that it can operate in the opposite sense, given that
the non-commission of a relevant prior infringement by the
controller or processor has not been legally provided for as a mitigating factor,
but rather must be treated as a neutral factor, that is, one that has no
effect for or against the sanctioned party, as provided by the
EDPB in the Guide to Fines, which states that:
“The existence of prior infringements may be considered an
aggravating factor in the calculation of the fine. The weight given to this factor must
be determined taking into account the nature and frequency of the
prior infringements. However, the absence of prior
infringements cannot be considered a mitigating factor, since
compliance with the GDPR is the norm. If there are no prior infringements,
this factor may be considered neutral.”
28001 – Madrid 6 sedeagpd.gob.es 101/173
The aggravating, rather than mitigating, nature of the offense is a well-established doctrine in Spanish case law regarding administrative sanctions.
In matters of personal data protection, one could cite, for example, the
Judgment of the National Court of May 5, 2021, appeal no. 1437/2020, which states:
“It considers, on the other hand, that the non-commission of a prior infringement should be taken into account as a mitigating factor.
Well, Article 83.2 of the GDPR establishes that the following must be considered for the imposition of the administrative fine:
“(e) any prior infringement committed by the controller or the processor.” This is an aggravating circumstance; the fact that the conditions for its application are not met means that it cannot be taken into consideration,
but it does not imply or allow, as the plaintiff claims, its application as a mitigating factor.”
or “Likewise, no damages have been proven, nor is there a report on
hypothetical damages, nor is there any claim from
any user.”
Again, none of these circumstances are provided for in the
applicable regulations as a factor in determining the severity of the penalty, therefore
they cannot be considered as a mitigating or aggravating factor of the
liability, and the respondent does not allege the application of any rule.
or “Regarding the processing of data, the breach does not affect data of
special categories or data of minors.”
The factor in determining the severity contained in Article 83.2, “g) the
categories of personal data affected by the infringement,”
operates as an aggravating factor, and it was not included when determining
the penalty, as the respondent's initial
allegation that the personal data being processed
contained in the table “***TABLE.1,” which was the target of the cyberattack, did not
include personal data, as defined in Article 9.1 of the GDPR, was considered proven.
Regarding the absence of data on minors, it is understood that
this circumstance has not been proven by the respondent, who has not provided
sufficient documentary evidence for this agency to verify the
age of the individuals whose personal data was included in the
aforementioned table. However, if applicable, it is
considered only as an aggravating factor and not a mitigating one, according to
Article 76.2, which refers to considering: “f) The impact on the rights
of minors.” Since, as with the previously alleged grounds, the
wording of the provision is positive, referring to when it is proven
that the rights of minors have been affected, and not to when they have not
28001 – Madrid 6 sedeagpd.gob.es 102/173
been.
- Regarding the corrective measures adopted, it is noted that: “The corrective measures adopted by CECOTEC have not been assessed without having been
requested or required by the Spanish Data Protection Agency (AEPD), pursuant to Article 83, paragraph 2, point (i)
when the measures indicated in Article 58, paragraph 2, have been
previously ordered” against the controller or processor concerned
in relation to the same matter, compliance with said measures; and
point (c), which refers to “any action taken by the controller or processor
to mitigate the damage suffered by the data subjects.”
Before assessing whether any of these circumstances
should be applied as mitigating factors, it should be clarified that the respondent makes
statements that do not coincide with the proven facts of this
proceeding:
First, regarding the list of corrective measures adopted. As analyzed in the assessment of the evidence in legal basis 3.2,
to determine whether the aforementioned mitigating circumstances apply,
one must begin with the list of corrective measures whose existence
is considered justified in the eighth proven fact of this
proposal, which does not coincide with the list enumerated in the statement of allegations. These measures include both those identified and
substantiated during the investigation phase in the API report,
as well as the disabling of access to the platform via the internet, which
occurred after the initiation of the sanctioning procedure,
as verified in the Proceedings of June 3,
2024, by this investigating judge.
On the other hand, the respondent states that it adopted these measures
without prior request from this Spanish Data Protection Agency (AEPD), but the truth is that it has not
provided proof of the date on which each corrective measure was adopted,
since there is only dated documentation regarding
the following measures:
During the investigation phase, the following
documentation was provided as proof of corrective measures adopted after
the breach:
(…)
Furthermore, the disabling of internet access to the
platform occurred after the initial agreement,
although no proof was provided, this fact having been formally recorded
on June 3, 2024.
Finally, it is not true that the initial agreement did not take into account the adoption of all these corrective measures, since the
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 103/173
was assessed in legal basis XV, relating to the adoption of corrective measures by this Agency under Article
58.2 of the GDPR. The adoption of measures aimed at correcting the breaches committed could justify, where applicable, the non-adoption of corrective measures by this Agency. However, the
adoption of these types of measures, which should have been adopted prior to the breach but were not, cannot act as an exemption from liability, since they constitute the consummation of the alleged infringements. Nor can they be considered as a mitigating circumstance in determining the severity of the sanction, if they do not fall under the scenarios expressly provided for in subparagraphs f) and c) of Article 83.2 of the GDPR.
In this case, the mitigating circumstance provided for in Article 83.2(c), which refers to "any action taken by the controller or processor to mitigate the damage suffered by data subjects," cannot be applied, since the necessary conditions for its application are not met.
Therefore, firstly, its application must be ruled out since the corrective measures whose adoption has been proven in the eighth finding of fact are not actions taken to "mitigate the damage suffered by data subjects." CECOTEC denies in its submissions that any damage has been caused to data subjects, even requesting that a mitigating circumstance be applied for this reason, and also asserts that it is not necessary to notify the affected parties of the breach based on this same consideration. Therefore, it cannot
simultaneously claim to have mitigated the damage that it says
does not exist.
... Analyzing the corrective measures that have been adopted, it is confirmed
that this mitigating circumstance cannot be applied, since all the measures
were aimed at correcting this situation of non-compliance with the obligation
stipulated in Article 32.1 of the GDPR, referring to “appropriate technical and
organizational measures to ensure a level of security appropriate
to the risk, which, where applicable, include, among others (…). Furthermore, it is observed that
necessary measures, such as those indicated in
Article 32.1 a) “pseudonymization and encryption of personal data,” are still not included.
Therefore, their purpose is to strengthen the security of the platform, as
expressly stated in the letter from Response #1. None of them are aimed at
mitigating the damage caused to the data subjects.
Moreover, it should be noted that the respondent has not demonstrated
that it adopted these measures spontaneously before becoming
aware of the start of the investigation by this agency, which
occurred on August 8, 2023, when it was The first request for investigation has been notified. This is also a factor that must be assessed to determine whether it is appropriate to apply the same, as indicated in the EDPB Fines Guide.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 104/173
75. The adoption of appropriate measures to mitigate the damage suffered by data subjects may be considered a mitigating factor, reducing the amount of the fine.
76. The measures adopted must be assessed, in particular, in relation to the element of timeliness, that is, the moment at which they are applied by the controller or processor, and their effectiveness. In this respect, measures applied spontaneously before the start of the supervisory authority's investigation are more likely to be recognized by the controller or processor as a mitigating factor than measures applied after that point.
Furthermore, with regard to the mitigating circumstance in Article 83.2(f) of the GDPR,
referring to the “Degree of cooperation with the supervisory authority to
remedy the infringement and mitigate its possible adverse effects,” the application requirements are also not met, since,
as the EDPB Fines Guide points out:
“95. Article 83(2)(f) requires the supervisory authority to
take into account the degree of cooperation of the controller or the
processor with the supervisory authority to remedy the infringement and
mitigate its possible adverse effects.
96. Before further assessing the level of cooperation established by the
controller or the processor with the
supervisory authority, it should be reiterated that the general obligation to
cooperate applies to both the controller and the processor under Article
31 of the GDPR, and that a lack of cooperation may lead to the
application of the fine provided for in Article 83(4)(a).” of the
GDPR. Therefore, the ordinary duty to
cooperate must be considered mandatory and, consequently, neutral (and
not a mitigating factor).
97. However, where cooperation with the supervisory authority
has had the effect of limiting or preventing the negative consequences
for the rights of individuals that might otherwise have
occurred, the supervisory authority may consider this a
mitigating factor within the meaning of Article 83(2)(f) of the GDPR,
thereby reducing the amount of the fine. This may be the case, for
example, where a controller or processor has
responded specifically to the requests of the supervisory authority
during the investigation phase in that particular case, which has
significantly limited the impact on the rights of individuals
as a result.”
28001 – Madrid 6 sedeagpd.gob.es 105/173
As the EDPB points out, the measures taken by the respondent after The
cyberattack is the result of compliance with an obligation of the
controller of all processing, provided for in Article 31 of the GDPR, the
failure to comply with which could lead to the commission of a different and
independent infringement from those already charged. Failure to adopt these measures may
lead to the commission of a new infringement and the
application of a separate fine, as established in Article
83.4(a) of the GDPR. It is not a mitigating factor but a neutral one.
It is considered that in the present case, they cannot be applied as a mitigating
factor, since the corrective measures adopted were not
the result of “cooperation with the supervisory authority,” as
most of them were adopted during the investigation phase, without
any request being made for their adoption by
this Agency, and the one adopted after the initiation agreement, referring to
the disabling of the platform, was not included among the possible
corrective measures indicated in paragraph XV of the initiation agreement. Furthermore,
it has not been demonstrated, as already stated, that its adoption “has had the effect of limiting or preventing negative consequences for the
rights of individuals.”
- Thirdly, the allegations point out that “in general there is a clear lack
of proportionality in setting the amount of the sanction: the fact that the maximum quantitative limit is so broad does not justify this amount, which must
be adjusted to economic capacity and is considered disproportionate according to
case law and Article 29 of the LRJSP.” Several judgments are cited,
such as the Supreme Court ruling of June 2, 2003, and the Supreme Court ruling of July 29,
2014 (Administrative Law Chamber, Section 1).
In this regard, it can be confirmed that the determination made in the initial agreement
was proportional, and the
circumstances taken into account for the initial determination of the sanction were sufficiently justified. And that
the fines set therein were not only not disproportionate, but
were set low considering the circumstances, despite
the defendant's refusal to notify those affected of the breach.
Furthermore, the initial agreement is considered to have acted prudently: (i)
starting with 6 individuals affected by the breach in the case of infringements of
Article 5.1.f) and 34 of the GDPR, which should be increased in light of the
evidence presented; (ii) proposing a fine of €750,000 for the
infringement of Article 32 of the GDPR, despite the established situation
of absolute lack of protection for the personal data
contained on the ***SOFTWARE.1 platform, when the maximum limit is
2% of the company's turnover; (iii) and interpreting the time limit
in a manner favorable to the respondent, although this aspect could be reduced,
28001 – Madrid 6 sedeagpd.gob.es 106/173
in accordance with the interpretation made in this proposal.
- Finally, the respondent explains why it believes the fines imposed for
each infringement are “completely disproportionate because the
following circumstances were not considered”:
a. Regarding the fines imposed of €140,000 for the
infringement of Article 5.1.f) of the GDPR and €750,000 for the
infringement of Article 32 of the GDPR, the respondent believes that
they are completely disproportionate given the lack
of evidence that any damage has materialized and that
there is no complaint or claim from any user, coupled with the fact that the
accessed data of the 6 actual users would not currently allow
identity theft since the
full ID/Tax Identification Number (DNI/NIF) was not available, only the number and letter, nor the
names and surnames. Since corrective measures were adopted
without being required by the Spanish Data Protection Agency (AEPD), their severity and
reduction should be considered.
b. Regarding the imposed fine of €100,000 for the infringement of
Article 33 of the GDPR, should it be found to have occurred, the
amount is completely disproportionate given that
the breach was voluntarily reported by CECOTEC, there are no
user complaints, and the delay with respect to
those 72 hours is only 3 days because the
full extent of the breach was unknown, and there were also public holidays
within the aforementioned period, as was demonstrated.
c. Regarding the imposed fine of €40,000 for the infringement of
Article 34 of the GDPR, it should be noted that, should its
occurrence be found, the amount is completely
disproportionate, especially considering that there is only
evidence of 6 actual data subjects affected, their data is not
sensitive or of a special category, and would not currently allow
identity theft since the full
ID/Tax Identification Number is not available, only the number and letter, nor the names and
surnames.
This reiterates the arguments regarding the failure to apply the
mitigating factors that, in the opinion of the respondent, should be considered,
the dismissal of which has already been justified. We must refer to the
arguments already presented to avoid unnecessary repetition.
4.2. Response to the allegations made after receiving a copy of the file, dated May 8 and 13, 2024.
After receiving a copy of the file, CECOTEC submitted a second document of allegations to the initiation agreement, dated May 8 and 13, 2024 (hereinafter,
Allegation AI #2), in which, having had access to the file, it formulated, in summary, four
additional allegations to those already made:
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 107/173
FIRST. - LACK OF GRADUATION.
It contains the following allegations, which must be dismissed based on the following:
Regarding the claim that: “It appears on page 222 of the administrative file
relating to ‘SIGNIFICANT EVIDENCE FOR THE GRADING’ that the
Inspector only considered the CECOTEC turnover figure for the 2022 fiscal year as a criterion for the grading,” it should be noted
that the agreement initiating the sanctioning proceedings, which is responsible for
setting the initial grading of the sanction to be imposed for each
alleged infraction, did not solely consider this evidence of
turnover, the mention of which in the inspector's report is neither
exhaustive nor limiting.
The proof of this is that the initial agreement contains a detailed description of the multiple factors considered in each infraction (legal grounds V, VIII, XI, and XIV),
which take into account CECOTEC's turnover as one of the starting points for calculating the fine amount, but adjust the penalty by considering multiple other factors that affect the nature, duration, and severity of the infraction, the degree of negligence committed, etc.
Regarding mitigating circumstances, it is reiterated that the initial agreement briefly mentions the severity, nature, and duration of each infraction, in the opinion of the Spanish Data Protection Agency (AEPD), but the Agency has not considered any criteria for adjusting the penalties to mitigate them,
as already pointed out in its initial statement of allegations. This acknowledges that the initial agreement does not adjust the penalty solely based on
turnover, as they had just stated.
It is added that: “In accordance with Guidelines 04/2022 of the European Data Protection Board on the calculation of fines, following the structure of the
GDPR, after having assessed the nature, seriousness, and duration of the
infringement, as well as its intentional or negligent nature, which
is solely and exclusively what the Spanish Data Protection Agency (AEPD) has considered in this case, the
supervisory authority must take into account the remaining aggravating and mitigating factors
listed in Article 83, paragraph 2, of the GDPR, as well as the
categories of personal data affected. And yet, CECOTEC reiterates
that the AEPD has not assessed the limited relevance of the categories of personal data
affected, nor that there is no history of repeat infringements by
CECOTEC, and the degree of cooperation with the
supervisory authority to mitigate risks has also been disregarded.
And they reiterate that Article 76.2 of the Spanish Data Protection Act (LOPDGDD) states that
Two circumstances that are not present in this case must be taken into consideration to mitigate or aggravate the penalty.
28001 – Madrid 6 sedeagpd.gob.es 108/173
are: c) The benefits obtained as a consequence of committing the infraction. f) The impact on the rights of minors.
Therefore, since they are not present, they must be considered to mitigate the penalty.
This being a reiteration of the allegations already made, and the only new element being the
mention of the Fines Guide, which has already been examined in response to the first allegations, we refer to what has already been said in this regard.
SECOND. – REGARDING THE ATTACK BY A THIRD PARTY (HACKER) AND THE COMMUNICATION MAINTAINED BY THE INSPECTOR.
It is understood that a response has already been given regarding all the issues raised in this allegation, given that:
• The status of victim of a CECOTEC cyberattack, as well as
the fact that no damages have been proven and that
CECOTEC's presumption of innocence remains valid. This was addressed in
legal basis 3.2 when establishing the disputed fact of the defendant's
culpability regarding the commission of the infringement defined in Article 5.1.f) of the
GDPR.
• They indicate that upon receiving the copy of the email dated August 4, 2023, which
the inspector sent to the malicious actor, the defendant noted that it contained the
email address of a potentially identifiable perpetrator, and therefore
informed them that the corresponding complaint would be filed with the National Police.
This copy was attached in a subsequent document dated September 24, 2023, and was added to the
file. However, the complaint filed aims to determine the possible
criminal liability that could arise from the data breach
resulting from the cyberattack. However, it is not relevant for the purposes of determining the
concurrent administrative liability for the breaches of data protection regulations
attributed in the present case to the data controller.
• Likewise, the respondent states that there is no record that the Spanish Data Protection Agency (AEPD) provided it with said data in any request, which would have been useful and would not
have prejudiced the investigation; and that INCIBE also failed to provide it,
stating that it could not determine whether the information was truthful. As already
indicated when establishing the proven facts acknowledged by the respondent, in
legal basis 3.1 of this Proposal, it is established that the respondent possessed the email address of the malicious user from the first INCIBE alert email, which not only mentioned the user's name,
but also provided a link to the advertisement containing all the information
necessary to contact them.
28001 – Madrid 6 sedeagpd.gob.es 109/173
For all the reasons stated above, it is considered that the charges of the four administrative infractions, as initially alleged, should be upheld, with the modifications resulting from the investigation carried out, regarding the severity of the sanctions for the infractions, as detailed throughout this legal basis. >>
V.
Response to the objections against the Proposed Resolution.
On March 18, 2025, CECOTEC submitted a statement of objections to
the proposed resolution of the procedure, without attaching any documentation,
stating in a total of six objections (preliminary, and first through fifth) that it should be
dismissed in its entirety based on the following reasons:
PRELIMINARY OBJECTION: CECOTEC reiterates the objections and grounds already
made in previous submissions, to which the same response applies as
that made in the proposed resolution of this procedure, which is fully endorsed by this Agency.
FIRST OBJECTION: Disputed Facts. This is merely an introductory heading to
objections two through four, which does not contain any objections, and in which the three facts declared as disputed in the proposed resolution are mentioned.
o Number of records ultimately affected, the Agency understanding that
this would be nine hundred and ninety-three (993) records.
o Effectiveness of the technical and organizational security measures
in place at the Company.
o Determination of the starting date in relation to the notification period
of the security breach.
SECOND ALLEGATION: Regarding the number of records ultimately affected.
2.A. Principle of culpability and proportionality in relation to the infringements
contemplated in Articles 5.1.f) and 32 of the General Data Protection Regulation (GDPR). Lack of a causal link.
- First, the respondent emphasizes that it has not been proven that the cyber
attacker was able to exfiltrate the personal data contained in the table
“***TABLE.1” of its platform ***SOFTWARE.1 due to the company's negligence. This has already been addressed in Legal Basis 3.2, when
analyzing the disputed fact of the scope of the breach and the number of records
affected, to which we refer.
Therefore, the main issue of proving the defendant's culpability
in the breach of the duty of confidentiality of the personal data
accessed and exfiltrated by the cyber attacker is resolved. This culpability is based
on the failure to adopt encryption and pseudonymization measures that
would have prevented the cyber attacker from knowing and using the
28001 – Madrid 6 sedeagpd.gob.es 110/173
content of the personal data that was exfiltrated, and not on the failure to adopt measures to prevent the cyber attack, which has not
been proven.
However, it is necessary to clarify some statements made by the respondent in that
allegation regarding the proposed resolution indicating that there are
reasonable doubts about the scope and size of the table and the records, since
it has not been possible to verify the input vector, the total number of
records that the cyber attacker claimed to have (more than 1,086,000) does not match
the total number of records in the table, there is an added "date upd" field
that is not present in the cyber attacker's sample, and the number of
matching records was 933 people according to the proceedings of February 14, 2025.
In this regard, the following should be clarified:
First, the reasonable doubts stated in the proposed
resolution referred to the fact that the cyber attacker had the
1,086,185 records he claimed to have when he contacted the inspector,
but it has never been stated that there is any reasonable doubt that he
had The 1,000 records provided to the inspector as
sample 2, declaring as a proven fact that the cyberattack affected
a total of 933 people whose personal data could be
identified by comparing the aforementioned sample of 1,000 records with the data in
table ***TABLE.1, which was provided by CECOTEC during the
testing phase, through a Proceeding dated February 14, 2025. Records and
affected parties whose coincidence has not been denied by CECOTEC in its
allegations against the proposed resolution, which focuses on denying
that the cyberattack had access to the more than one million records it
claimed to have, which is an uncontested issue in the proposed
resolution, as already stated.
Therefore, after the submission of arguments against the proposed resolution, it can be stated unequivocally that the scope of the gap is
set at 933 people, and that this is a fact acknowledged and not
disputed by the respondent throughout its submission.
Furthermore, regarding the complete lack of agreement between the registration fields
contained in sample 2 and the table provided by CECOTEC,
it should be noted that, as stated in FD 2.1. “In conclusion, it follows that the data structure contained
in the two samples provided by the malicious actor and the table
“***TABLE.1” contained in the old platform ***SOFTWARE.1 1.6
customized by CECOTEC has 24 matching fields,
the only difference being the inclusion of an additional field in the Excel document
provided by CECOTEC, extracted from the table ***TABLE.1, which is
the one referring to “date_upd”, corresponding to the updated date, which is
a field that is automatically generated with each update of the
28001 – Madrid 6 sedeagpd.gob.es 111/173
platform performed.” Having alleged this lack of matching in the
objections to the proposed resolution, it should be noted that: (i) this date_upd field
is compatible with the automatic generation of a list from the
database that is added when updating the tables contained in the database; (ii) and the lack of a match in this field does not preclude the fact
that the cyber attacker has access to the personal data appearing in
the other fields included in the sample, which do fully match
the table.
2.B) Lack of a graduated penalty.
Regarding the absence of harm caused to affected clients, and the
lack of culpability, CECOTEC points out that despite acknowledging
that there is no culpability by partially upholding this claim, this lack of culpability has not been
taken into account in the proposal, nor have other
facts that have been expressly recognized by the Agency as
factors for accelerating the imposed penalty, even increasing the amount
imposed, which contravenes the principle of culpability and proportionality,
given that Article 29.3 of Law 40/2015.
- Regarding the lack of evidence that CECOTEC was
at fault for failing to prevent the exfiltration of personal data, being
the victim of a cyberattack, and its impact on the severity of the penalty,
we refer to what has already been stated in Legal Basis III.
It should be added that this Agency has considered the requirement of
culpability fulfilled for each of the four alleged infringements in these
proceedings, understanding in each case that there was gross negligence
on the part of the respondent, due to the omission of its obligations as the data controller.
In the specific case at hand, the issue is limited to culpability in the
commission of the infringement of Article 5.1.f) of the GDPR, in which the
proposal partially upheld the allegation that the causal link between the access to personal data by the
cybercriminal and the deficiencies and vulnerabilities of the platform (due to
the failure to adopt the measures that would have been necessary to
prevent the exfiltration of personal data) had not been
proven. However, it is understood that the reasons why this
partial acceptance is not a full acceptance have been
justified in the proposal and in this resolution, since the requirement of
culpability for this infringement is met by the failure to adopt the
encryption measure for personal data, which would have prevented the
cyber attacker, even if they had managed to extract the data, from knowing its
content, making it public, and using it.
Thus, given that culpability is a typical requirement, the following is considered to be in accordance with the law:
and the Principles of Culpability and Proportionality
the gradation of the sanction under Article 5.1.f) of the GDPR, which was made in the proposed resolution,
whereby it is considered that a degree of
gross negligence can be imputed in the actions of the respondent, for failing to protect
28001 – Madrid 6 sedeagpd.gob.es 112/173
confidentiality, applying the gradation circumstance of Article
83.2.b) of the GDPR, without thereby reducing the amount of the sanction to be imposed
with respect to that initially set in the commencement agreement, based on
the following:
“(…) it is understood that there was negligent action on the part of the
company, for not having applied the necessary encryption and
pseudonymization measures to its database, which would not have
prevented the cyber attacker from accessing illegitimately to the
same, and extracted or usurped them, but if he had prevented the
breach of confidentiality of the data from occurring, since
had they been encrypted the cyberattack would not have been able to
know their content, decrypt them without having the key, nor, therefore,
use them, nor publish them nor transfer them to third parties.”
- The respondent argues that the fine has been increased by 155% based on the number of affected parties and that it is disproportionate. This allegation is upheld by the Spanish Data Protection Agency (AEPD), and through this resolution, the amount of the fine is set as indicated in the initial agreement; that is, €140,000.
- Finally, the respondent points out that page 7 of the proposed resolution acknowledged that “there is no evidence of damages caused to potentially affected clients,” without considering this as a mitigating factor, which violates Article 29 of Law 40/2015 on the Legal Regime of the Public Sector. However,
the paragraph to which the respondent refers is located within the background
facts, and it merely sets forth/summarizes the allegations made by the
respondent itself in its response of August 30, 2023, to the initial response
to the request. This sentence is not an assertion by this
agency, but rather by the respondent itself, transcribed to record in
the background facts its position regarding the request made.
Therefore, there is no acknowledgment whatsoever by the agency regarding the absence
of damages. Furthermore, we should refer to what was already stated in the
Legal Basis above regarding the reasons why the absence
of damages—which has not been proven—cannot be considered a mitigating factor
but is only considered an aggravating factor if damages are
proven.
THIRD. – Regarding the effectiveness of the technical and
organizational security measures in place at the Company.
3.A) Infringement of the principle of legality and lack of liability under Article 5.1 f) GDPR.
The proposed resolution having justified the culpability
of the infringement of Article 5.1 f) for failing to adopt the technical measures
for encryption and pseudonymization of the personal data that were exfiltrated,
the respondent states that:
- On the one hand, it indicates that Article 5.1 f) GDPR does not specify that the appropriate
28001 – Madrid 6 sedeagpd.gob.es 113/173
protection measure is the pseudonymization and encryption of data,
but rather refers to the adoption of appropriate technical or organizational measures
in general. According to the respondent, this is because
as indicated by the EDPB in its Guidelines 04/2022, Article 5.1.
f) The GDPR is a generic provision that regulates the principles of data protection,
while the integrity and confidentiality measures
are specifically addressed in Article 32 of the GDPR. And in the
present case, the cyber attacker's entry point is unknown; therefore,
it cannot be determined whether the technical or organizational security measures in place at the Company were
appropriate, precisely because it is impossible to determine how the attacker gained access and, therefore,
which measures the hacker bypassed.
This argument can be dismissed because:
First, the aforementioned EDPB Guidelines 04/22 on calculating fines
(Guide to Fines) do not state anywhere that Article
5.1.f) of the GDPR establishes a principle but that the measures for
protecting integrity and confidentiality are addressed
only in Article 32 of the GDPR. This is an interpretation
of the challenged argument, which is based on several erroneous premises. First,
because it is not even true that Article 32 of the GDPR contains a
list of measures necessary to be adopted by every data controller (rather, these will depend on the processing and ensuring a level of security appropriate to the risk), and second, because
Article 32 of the GDPR is not the only provision from which the adoption of measures aimed at guaranteeing the confidentiality of personal data is derived, as will be pointed out in the following legal grounds.
Or, secondly, because it has already been stated that the liability of
the party being held responsible for the infringement of Article 5.1.f) of the GDPR is not based on the failure to adopt measures that would have prevented the hacker from accessing the personal data.
And lastly, because it is also not true that Article 5.1.f) does not
refer to the need to adopt measures that guarantee
confidentiality, since its literal wording is
precisely the following: “f) processed in such a manner as to ensure
appropriate security of personal data, including
protection against unauthorized or unlawful processing and against
accidental loss, destruction or damage, by implementing
appropriate technical or organizational measures (“integrity and
confidentiality”). The encryption and pseudonymization of personal data
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 114/173
is undoubtedly an appropriate measure to protect the confidentiality
of said data.
- And on the other hand, the respondent points out that it is not true that there was a
total absence of encryption measures, since the communication between the
access devices and the platform was encrypted and the backups
were also in place, as noted on
August 30, 2023. This issue has already been addressed in
Legal Basis 3.2, which outlines the reasons
why it cannot be considered proven that the defendant had
adopted encryption measures for the "at-rest" database that
contained the personal data hosted on the defendant's servers
that were the subject of exfiltration.
3.B. Infringement of Article 32 GDPR, lack of culpability, and lack of
proportionality.
- First, it must be stated that the defendant's assertion
that there is no evidence of the vulnerabilities and the
insufficiency of the platform's technical and organizational measures existing
at the time of the cyberattack is untrue, since it should be recalled that all the
listed vulnerabilities were acknowledged in an internal email from the
Director of Cybersecurity himself, sent on April 14. 2023 to the DPD
of CECOTEC, which is confirmed and provided by the respondent itself in its
two written responses to the information requests during the investigation phase, and were therefore reflected by the inspector in his API report.
- Furthermore, it points out that the concept of
vulnerability should not be equated with that of insufficient technical or organizational measures,
as they are not exactly the same, although they are closely
related, which is true, without the proposal having made
any conceptual equivalence, having been related as part of the
measures not adopted within the breach of Article 32 of the GDPR,
but in different sections. That is, in the ninth proven fact, which
contains them, and in Legal Basis VIII, several
preventive measures that were not adopted by the respondent before
the cyberattack are listed, distinguishing as the first of them the one referring to the
version vulnerabilities of the ***SOFTWARE.1 platform, from the other
measures not adopted by the controller that are detected during the
investigation.
Thus, the distinction is clear, as Legal Basis VIII
of the proposal states the following:
“-It has been detected that the platform suffered from the following deficiencies and
version vulnerabilities, which were necessary to protect the security of
the platform, and therefore, mandatory for the controller of the
28001 – Madrid 6 sedeagpd.gob.es 115/173
processing in accordance with the provisions of Article 32 of the GDPR. We refer to the finding that vulnerabilities existed that affected SERVICE.1 and SERVICE.2, that the platform was outdated and unsupported since 2019, and that it had internet access (with a username and password).
And it has been verified that the following measures necessary to guarantee a level of security appropriate to the risk had not been adopted:
Lack of adequate measures to guarantee the traceability of the platform: Those related to logs, the lack of monitoring, and the lack of access control for platform users, as detailed in the eighth proven fact.
• The platform's Risk Analysis needs updating (...).
• Lack of approval and implementation of a Security Breach Management Protocol
in accordance with regulations (...)”.
- Furthermore, the respondent points out that the proposal and the inspector's report
acknowledge that prior to the breach there was no absence or
non-compliance with technical and organizational measures, and lists
the 4 measures that were expressly recognized as having been adopted in the
eighth proven fact of the proposal. Therefore, it is not that it has not been
considered proven that these 4 measures were adopted, but rather that they have been deemed manifestly insufficient to guarantee
a level of security adequate to the risks arising from the processing of
the personal data contained on the platform. It is not true that there was
a total absence of preventive measures, and for this reason, both
the initial agreement and the proposed resolution and the present resolution refer to a situation of “almost absolute” lack of protection,
and not absolute. This is why the severity of the sanction is set at
750,000 euros, and not the maximum possible amount, which would be 10,000,000 euros or
2% of the company's turnover.
- And, on the other hand, the allegations point out that “it is surprising that, having
accepted the AEPD, the adoption of corrective measures by
CECOTEC (page 65) has not been taken into consideration as
a mitigating factor under Article 83.2.c) of the GDPR,” the company
being complained against disagreeing with the assertion that “they are not a mitigating factor but
a neutral one,” since, in its view, this is contrary to the Fines Guide
(Guidelines 4/2022), regarding which we should refer to the reasons that
were stated in the proposed resolution, which have been
made clear above.
- Regarding the allegation that “having indicated that the mitigating factor cannot
be applied because there was no request from the agency,
it understands that this fact must be taken into account when applying
the mitigating circumstance set out in art. 83.2.c) GDPR”. We should also refer
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 116/173
to the arguments made in the previous legal basis regarding
the different requirements necessary for the adoption of corrective measures
following the incident to be considered a mitigating circumstance, which
are not present in this case: (i) neither with respect to the mitigating circumstance of
Article 83.2.c) of the GDPR (any measure taken by the controller or
processor to mitigate the damage suffered by the
data subject), which does not apply because the measures adopted were to
strengthen the security of the platform and not to mitigate the damage, which the
defendant herself denies); (ii) nor with respect to the mitigating circumstance of 83.2.g (the degree
of cooperation with the supervisory authority in order to remedy the
infringement and mitigate the possible adverse effects of the infringement), since
the Fine Guide Guidelines state that these must be adopted
at the request of the data protection authority, otherwise it would not
constitute cooperation.
- It is insisted that the principle of proportionality has been violated, and that
the amounts of €300,000 and €750,000 are disproportionate since
the Agency has not taken into consideration any mitigating circumstances to reduce the
administrative fine. This allegation cannot be upheld
given that:
a) Circumstances are mentioned that do not apply in the present case,
as has already been explained on several occasions. We are referring to
facts that the party considers proven but are not, such as
the absence of culpability, the impossibility of determining the causal link,
or the limitation of third-party access; that only the
cyber attacker had access, and the lack of consequences for the interested parties since
no purchase the database by any third party. These last two facts are, moreover, impossible to verify in the present case.
b) Other circumstances mentioned in the allegations were taken into account when determining the penalty to be imposed, as has also been repeatedly stated (lack of knowledge of the entry point and the type of data affected).
c) Others were not considered because they did not meet the requirements to be considered a mitigating factor, as stated, such as the corrective measures adopted.
- Furthermore, they also deny that the breach management protocol did not exist prior to the breach and that it was not being applied in the company, given that the Data Protection Officer (DPO) itself, in its report of April 19, 2023, states that the procedure was followed, demonstrating that it existed previously and that training had been provided on the matter.
28001 – Madrid 6 sedeagpd.gob.es 117/173
Participation in training courses recognized as a The preventive measure
included in the ninth finding of fact, nor the mere
mention in the DPD report of compliance with the company's internal protocol,
is considered sufficient to conclude that the company was
applying an adequate Breach Management Protocol.
What the proposed resolution pointed out, and what has been demonstrated
by the evident failures committed by staff in detecting and managing the
breach, is that the company failed to fulfill its duty to
have and apply a breach detection and management protocol, for two
reasons:
“First, because it has been proven that they did not have a Breach Management Protocol
compliant with regulations, meeting the
requirements referred to in the EDPB Guidelines 09/22 on
breach notification, but rather a 2021 Security Incident Management Protocol, which did not meet the minimum requirements
to be considered a Breach Management Protocol.
And secondly, because the company did not apply its own Incident Management Protocol
from 2021 (which regulated how to detect a security incident and report a breach), the communication of which to employees and managers prior to the breach is not documented. (...)
In this case, as pointed out in response to the company's allegations,
it has been demonstrated that the 2021 Protocol was either unknown to the company's personnel or was not applied, since:
(i) the first cyber incident alert from INCIBE was received on April 5, 2023,
in the general inbox, but was not forwarded to those responsible for detecting and managing the breach as stipulated by said protocol; (i) nor was it
applied by the cybersecurity officer and the DPO, since the
officer himself indicated that sufficient certainty that a breach might have occurred was enough, not absolute certainty,
to make the notification, as both understood according to their
communications.”
And it should be added that if what the allegations to the proposed resolution now state is true, regarding the fact that the calculation of the
deadline for notifying this agency of the breach began on April 14,
when the cybersecurity officer informed the DPO of the actions taken, this would imply that the DPO would not have been involved from the
very moment he became aware of the alert received from
INCIBE, as is mandatory according to Article 38 of the GDPR, and
as stated in the Protocol.
- Finally, the respondent invokes other cases of personal data breaches
in which the Agency has imposed lesser sanctions for the
infringement of Article 32 of the GDPR, when the number of affected individuals was
greater.
Specifically, two cases are mentioned:
28001 – Madrid 6 sedeagpd.gob.es 118/173
or “Thus, in case PS/00179/2020 of AIR EUROPA, where
a total of 489,000 national and international data subjects were affected, with 1,500,000 records affected, a fine of €500,000 was imposed for infringement of Article 32 of the GDPR.
or Additionally, and in a much more recent case, in
EXP202210465 against Telefónica, in which the personal data of 1,407,257 data subjects was exposed, a fine of €500,000 was imposed for infringement of Article 32 of the GDPR.”
This allegation must be dismissed, since:
First, because there are no two identical cases that can be
equated when determining the penalty to be imposed for each
infraction, given that in each case, the starting point must be the volume of
business when dealing with companies, as is the case here, which is different
in CECOTEC compared to the companies being
compared. And, as was done in the
proposed resolution and is done in this resolution, all the
circumstances for determining the penalty in each case must be considered, which
must be assessed jointly, and not only the number of affected parties to which
the respondent appeals. Thus, in this case, multiple other circumstances have been considered
to assess the amount of the fine to be imposed, which the respondent does not analyze when making the comparison, such as
the duration of the infraction, the type of personal data, the
degree of culpability, the degree of non-compliance with obligations,
etc. All of this is necessary to ensure that the fine is
individualized, proportionate, effective, and dissuasive.
Secondly, the respondent, in comparing the number of
those affected by the breach, is starting from an erroneous
comparative premise that fails to consider the differences
between infringements of provisions—such as those contained
in Articles 5.1.f) and 34 of the GDPR—where the consummation of the
infringement requires a result (confidentiality breach); and
infringements of provisions—such as Article 32 of the GDPR—
where the infringement is consummated by the mere fact of not adopting the
means or complying with the obligations required by the regulation,
regardless of whether this non-compliance generates a
result, which would be sanctioned independently if
it infringes another legally protected interest.
Focusing on Articles 5.1.f) and 32 of the GDPR, the truth is that the
obligation in Article 5.1.f) of the GDPR requires a result (it is sufficient that
28001 – Madrid 6 sedeagpd.gob.es 119/173
the confidentiality or integrity of personal data is lost),
while the obligation in Article 32 of the GDPR is one of means (it is necessary
to design security measures according to the level of security
appropriate to the risk, implement them correctly and use them
appropriately, and the failure to do all or some of these things is what
is penalized).
And as a consequence, while those affected by the
infringement of Article 5.1.f) of the GDPR are those affected by the
loss of confidentiality resulting from the cyberattack to which
this case refers (933 people), those affected by the
infringements that generated obligations of means under Article 32 of the
GDPR were all the people whose personal data was
contained in the database (platform ***SOFTWARE.1) and were
being potentially put at risk on the date of the cyberattack, since
it did not have a level of security appropriate to the risk.
And in this case, it must be remembered that we are dealing with a
very high number of affected individuals whose personal data is
being placed at serious risk, since the respondent states
that table ***TABLE.1 alone contained data on more than
2,052,000 people. And the duration of the
infringement must be considered, as well as the fact that the degree of non-compliance with the measures gradually increased over time. It began
with the failure to adapt the processing to the provisions of the new GDPR once
it came into force. However, this non-compliance increased exponentially in 2019 when the company stopped contracting
for support and updating the platform, again in 2021 when
SERVICE.2 of the platform was shut down, as already mentioned, and in
2022, when the existence of a critical vulnerability in the version of SOFTWARE.1 used by the defendant was published.
This vulnerability was being exploited by cyber attackers to exfiltrate
data, and the defendant failed to download the update or "patch" published
by the manufacturer to correct this
vulnerability. Therefore, the duration of the infringement
has been continuous for more than 6 years (between the entry into force of the GDPR and
the present, in which all the necessary corrective measures
to adapt the processing to the GDPR have still not been adopted).
As the initial agreement and the proposal indicated, it is considered
that the infringement of Article 32 of the GDPR is especially
reprehensible in this case, since we are dealing with a systemic infringement, where the lack of organizational and technical measures that
protected the platform at the time of the cyberattack was almost absolute,
being limited to 4 isolated measures that were clearly insufficient.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 120/173
The most common security measures for any operating system or database connected
to the internet with a username and password were not being implemented, as the
platform had been unsupported since 2019, was outdated, and contained
critical vulnerabilities published by the manufacturer in 2022
that had not been patched because the relevant
update had not been downloaded, as stated in the inspector's report of November 2, 2023. Furthermore, there was a lack of
adequate risk management, given that the company
had not updated its risk analysis as of the date of the cyberattack,
and that the one carried out in 2022 was invalid and did not contain
all the concurrent risks or the analysis of their impact and
measures, with the rigor required of any data controller.
For all these reasons, €750,000 for the
infringement of Article 32 of the GDPR is considered a proportionate,
effective, dissuasive, and individualized penalty, given the
blatant lack of protection afforded to the personal data
contained on said platform.
FOURTH. – Disagreement with the starting date for notification of the
breach. Lack of proportionality of the infringement of Article 33 of the GDPR.
4.A) Starting Date.
- First, the company disagrees with the starting date for calculating the deadline for notifying this Agency of the breach being
April 13, 2023. It believes that the starting date for calculating the
72-hour period for notifying the breach should be April 17,
the date on which the Cybersecurity Director, after analyzing the situation
with the Data Protection Officer, responded to INCIBE, leading to
the breach being notified subsequently, on April 19.
The reason they give is that INCIBE should have contacted
the DPO's address directly and not a generic one that receives numerous
emails daily. Since the information was received through the generic address,
additional checks were necessary to verify that the
information provided was accurate. Therefore, both the Cybersecurity Director
and the Data Protection Officer needed
a few days to analyze and determine whether notification was necessary.
This argument must be rejected, maintaining that, as the
proposed resolution states in its Legal Basis XI, the calculation of the
time limit began on April 13, 2023, at 5:23 p.m., when the CECOTEC Cybersecurity Director
concluded his investigations by sending
a response to INCIBE informing them of the results.
28001 – Madrid 6 sedeagpd.gob.es 121/173
The same. Without any basis for being
accepted as the start of the count, since on that day there is only
an email sent by the cybersecurity director to INCIBE to verify
that there had been no phishing attempt and INCIBE's reply;
the first alert from INCIBE was received in
the inbox on April 5, 2023, the INCIBE alert was detected on April 12, 2023 when they sent
a reminder that was forwarded to the cybersecurity manager,
the DPD acknowledges in its report on April 13, 2023, that investigations were initiated and
concluded to verify that the 17 records in
sample 1 of the advertisement matched those of CECOTEC; and on April 14, 2023,
the cybersecurity manager sent a report to the DPD detailing
the investigations carried out and the conclusions reached.
Given this timeline, as evidenced by the communications
submitted as Annexes 6 and 7 of the initial response and acknowledged
in the DPO reports provided, it is in no way permissible to accept April
17 as the date on which the company "became aware of the
breach," to serve as the starting point for calculating the time limit.
The fact that INCIBE's initial alert was sent to the mailbox and not to the DPD's email cannot serve as an excuse to delay the start of the
counting to April 17, 2023 (or even April 14, 2023), given that:
First, it is not true that the delay was due to the need to
verify the email's origin, since the cybersecurity director responded to INCIBE on April 13, 2023, providing the
required information, and it was not until April 17, 2023, that he confirmed
whether the alert was a phishing attempt.
Second, the INCIBE alert's sending to the company's generic mailbox is considered valid, even though it has not been proven that the company provided the DPD's email address to it so that it could
serve as a communication channel, nor that it was included
in the company's privacy policy. Furthermore, it is established
that the staff in charge of the mailbox were unaware
that they should forward this email to the Data Protection Officer (DPO) and the cybersecurity officer,
as evidenced by an email dated April 19, 2023, in which the DPO
warns of this requirement and informs the staff
of the email addresses to which these alerts should be sent
urgently.
In this case, it is also noted that the staff handling the generic mailbox
ignored the provisions of the "Security Incident Management Protocol of 22-4-21," provided by the company,
which stated that (emphasis added):
28001 – Madrid 6 sedeagpd.gob.es 122/173
"Obligation to report any security event that affects
the confidentiality, integrity, or availability of personal data.
Any employee of the organization who becomes aware
of any indication of a security event or incident related to
personal data protection, through any of the
means indicated in section 2.1 of this document (regarding the
sources for identifying a security breach), must
report it within a maximum of 24 hours to the Data Protection Officer and their immediate supervisor and departmental superior."
- Alternatively, in the event that the notification is deemed to have been made
late, outside the 72-hour period, the respondent argues that the starting date
should be April 14 at 2:31 p.m., the moment when the Cybersecurity Director
informed the Data Protection Officer (DPO) of the investigations carried out, since,
until that moment, the DPO needed to know the conclusions reached
by the Cybersecurity Director in order to assess the scope and nature
of the breach. In this regard, it is argued that Article 33, when referring to the
72-hour period, includes the expression “(...)”, making the inclusion of
“(...)” essential. Furthermore, it is argued that the Spanish Data Protection Agency (AEPD) is demanding that the data controller
notify within 72 hours when there are merely suspicions (as
INCIBE itself initially considered) and not when there is certainty,
which is what is required by the GDPR.
However, this argument cannot be accepted, since:
First, as already stated in response to the objections to the
initiation agreement, the date from which the breach is known is the date from which there is a “reasonable degree of
certainty that a breach has occurred,” without requiring
absolute certainty, as the company's own Incident Management Protocol, in place since 2021, pointed out. Specifically, it is worth
recalling that point 40 of the EDPB Guidelines 09/2022 on
breach notification expressly states when a breach is considered to have been known:
“40. It should therefore be clear that the controller is obliged to act upon any initial alert
and to determine whether or not a breach has occurred. This
brief period allows for some investigations to be carried out and for the controller to gather evidence and other
relevant details. However, once the controller
of processing has established with a reasonable degree of
28001 – Madrid 6 sedeagpd.gob.es 123/173
certainty that a breach has occurred, if the
conditions of Article 33(1) of the GDPR are met, it must
notify the supervisory authorities without undue delay and, where
feasible, within a maximum period of seventy-two hours. If a
controller does not act promptly and it is
evident that a breach has occurred, this could
be considered a failure to notify pursuant to
Article 33 of the GDPR.”
Therefore, the first point to clarify is that this Agency is not
requiring notification based on “suspicions” as indicated by the
complainant, but rather that notification be made when this reasonable degree
of certainty exists, which undoubtedly existed in the present case.
It wasn't that there were suspicions, but rather that it has been established that on
April 13, 2023, the cybersecurity director had evidence that would have allowed him to determine that there was a "reasonable degree of certainty" that a breach had occurred, affecting, at
at least, all the personal data included in the 17 records of the initial sample that had been published by the cyber attacker. And he reported this to
INCIBE.
A separate issue is that he did not carry out a proper analysis of the breach due to a lack of awareness of the company's own incident protocol
2021, which expressly stated that absolute certainty that the malicious actor had accessed the entire database was not required, as also determined by
EDPB Guidelines 09/2022. Had the necessary mechanisms, procedures, and measures been applied to detect the breach, analyze and assess the risks, respond to it with appropriate measures, and report it, the data controller could have acted with the diligence expected of them. However, it has been established that there was a lack of diligence both in detecting the breach before initiating the investigation phase and after the investigation concluded. This negligence included errors in assessing the breach and its associated risks, as well as in communicating with the Data Protection Officer (DPO), notifying the agency of the breach within the established timeframe, and communicating the breach to the affected parties.
It should also be noted that in this case, the starting point of the timeframe is being interpreted in favor of the defendant. Since it is established that the data controller did not
act diligently and with due delay on several occasions: (i)
by failing to detect the first incident alert sent on 5-4-23, (ii) and
by detecting the second incident alert on 12-4-23, further delaying the
28001 – Madrid 6 sedeagpd.gob.es 124/173
start of the investigation period by requesting the content
of said email again from INCIBE - when it was in its generic
mailbox - and wasting another day until it was received. And yet,
this Agency has applied an interpretation favorable to the company, understanding that the time period did not begin on April 5th or 12th,
but rather on April 13th, 2023, when the Director of Cybersecurity responded to INCIBE. This interpretation is based on the understanding that the "brief investigation period" of the breach, which, according to
Directive 09/22, was necessary to verify whether the 17
records included in the advertisement sample were within
any of CECOTEC's databases, had concluded at that time. It is understood that at this point, sufficient evidence was available to
determine that there was more than reasonable certainty that
a breach had occurred in the aforementioned table ***TABLE.1, which
affected at least 6 users. Therefore, the time period for calculating the notification to this Agency began
at that point. The fact that
it is not recorded that he involved the DPD from the beginning of
the checks, and waited an extra day to
communicate the result of his investigations via email
can serve as an obstacle to further delaying the notification deadline, which had already been delayed since April 5, 2023, due to the lack
of an adequate application of the breach management protocol.
Furthermore, there is evidence, established in the proven facts and detailed in Legal Basis XI of the
Proposed Resolution, and XII of this Resolution, which leads
to the conclusion that the moment the respondent became “aware of
the breach” was April 13, 2024, when the cybersecurity director
concluded the investigations and determined that a breach had occurred
with a “reasonable degree of certainty,” informing INCIBE of this, with the respondent itself (DPD report) acknowledging
that it was then that it “became aware of the breach,” among other
multiple pieces of evidence.
Likewise, delaying notification until it can be verified “with absolute certainty”
that the cyberattack has affected all the records that the malicious actor
claimed to have in the advertisement (almost one million records
corresponding to users filtered by telephone number) is not
an excuse to delay the notification period, since, as
the previous legal basis and the proposed
resolution indicate, Article 33.4 of the GDPR allows for
gradual notification of the breach in these cases.
Article 33 itself, in paragraph 4, establishes the possibility of
gradual notification by stating:
28001 – Madrid 6 sedeagpd.gob.es 125/173
“4. If it is not possible to provide the information simultaneously, and to the extent that it is not possible, the information shall be provided
gradually without undue delay.”
Therefore, it cannot be understood that notification to the supervisory authority requires the controller to have “full knowledge” or
“full awareness” of the existence of a personal data breach
and all its elements, thus completing the meaning of “being aware” referred to in paragraph 1.
In short, the GDPR recognizes that there will be situations in which the
complexity of the personal data breach requires further actions and
investigations by the controller. However,
these circumstances do not, under any circumstances, exempt the controller from communicating
to the supervisory authority as quickly and efficiently as possible, even
if done gradually. This is the position taken in
Guidelines 9/2022, in paragraphs 56 et seq., which we have referred to above.
56. Depending on the nature of the breach, it may be
necessary for the controller to continue investigating
to establish all relevant facts related to the
incident.
57. This means that the GDPR recognizes that data controllers
will not always have all the necessary information
about a breach within 72
hours of becoming aware of it,
since complete and comprehensive details of the incident may not always be available during this initial
period. As such, it allows for phased notification.
This is more likely to occur in the case of more complex
breaches, such as some types of cybersecurity incidents
where, for example, a detailed
forensic investigation may be necessary to fully determine the
nature of the breach and the extent to which personal data have been
compromised.
Consequently, in many cases, the data controller will need to
investigate further and follow up with additional
information at a later stage. This is permissible, provided that
the data controller justifies the delay,
in accordance with Article 33(1) of the GDPR (...).
In this regard, applying a "teleological or purposive" interpretation of
the rules, it is important to bear in mind the purpose of the duty to
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 126/173
notify the supervisory authority established by the EU legislator.
The purpose of Article 33, as it is currently conceived,
based on the principles of speed and immediacy regarding the
notification to the supervisory authority by the controller, is
to ensure the maximum guarantees for potential data subjects affected by
personal data breaches. In this respect, it is worth highlighting
Recital 85 of the GDPR:
"85. If appropriate measures are not taken in a timely manner, breaches
of the security of personal data may entail physical, material, or immaterial harm and damage to natural persons,
such as loss of control over their personal data or restriction of their rights, discrimination, identity theft, financial losses, unauthorized reversal of pseudonymization, damage to reputation, loss of confidentiality of data subject to professional secrecy, or any other significant economic or social harm to the
natural person concerned. Therefore, as soon as the controller becomes aware that a personal data breach has occurred,
the controller must, without undue delay and, where feasible, no later than 72 hours after becoming aware of it, notify the personal data breach
to the competent supervisory authority, unless the controller can demonstrate, in accordance with the principle of accountability,
the improbability of the personal data breach resulting in a risk to the rights and freedoms of natural persons. If such
notification is not possible within 72 hours, it must
be accompanied by an indication of the reasons for the delay,
and information may be provided in stages without further
undue delay.”
Guidelines 9/2022 express the same view:
“58. The objective of the notification requirement is to encourage
controllers to act promptly in the event of a breach, to contain it and, where possible, recover the compromised
personal data, as well as to seek relevant
advice from the supervisory authority. Notifying the
supervisory authority within the first 72 hours
can enable the controller to ensure
that decisions about whether or not to notify individuals
are correct.”
28001 – Madrid 6 sedeagpd.gob.es 127/173
In short, notification to the supervisory authority allows, on the one hand, receiving guidance on the need to communicate the
personal data breach to the affected parties, but it also empowers
the authority to act, in the exercise of its powers—and whenever
it deems it necessary—and to exercise the powers that the
GDPR expressly attributes to it in Article 58, in particular, the
power enshrined in Article 58.2(e) “to order the controller
to communicate personal data breaches to the data subject,” although there may also be
other powers, depending on the circumstances of the specific case, such as
imposing temporary or permanent limitations on processing
(58.2(f)), a decision that, in any case, corresponds to the
supervisory authority and which must not be hindered by the
controller.
Failure to comply with Article 33 entails a deprivation of the
exercise of the powers of the supervisory authority, which, if it is unaware of the facts, cannot act (or decide not to), to the detriment, moreover, of the rights and freedoms of the affected parties, since personal data breaches imply or may imply the loss of control that they have over their own personal data, the guiding principle of the GDPR.
At this point, the CJEU judgment of 24 September 2024, in
case C-768/2021, goes further, recalling that the supervisory authority
will sometimes be obliged to intervene based on the
facts of which it becomes aware, and therefore the lack of
notification by the controller constitutes an interference with its
obligations.
And it is not only the lack of notification that prevents the supervisory authority
from acting according to the circumstances of the specific case, but also
late notifications, depending on the time elapsed since the
controller became aware, undermine the objective pursued by
Article 33 of the GDPR and leave this provision meaningless, by preventing
action by the supervisory authority or a swift reaction by
the data subjects. Guidelines 9/2022,
paragraph
40, which we referred to earlier, express this view.
In short, the obligation to notify the supervisory authority is not
a mere formal communication obligation, but rather,
a substantive obligation whose
28001 – Madrid 6 sedeagpd.gob.es 128/173
non-compliance has negative implications that ultimately
affect those impacted by a personal data breach.
In the present case, it is considered that the start of the time limit should not be delayed until the 14th (when the Cybersecurity Director sent a detailed report to the company's Data Protection Officer),
based on the argument alleged by the respondent that it was then
that the Data Protection Officer was able to learn of the breach and assess its scope, given that
had the company complied with its incident management protocol and the obligation stipulated in Article 38 of the GDPR, the company's
Data Protection Officer should have been involved in the detection process
from the beginning, and the start of the time limit should not be delayed by one more day simply because the technical officer in charge of conducting the
investigation and analysis decided to communicate said information to their
Data Protection Officer the following day.
It should be remembered that the obligation to notify the breach falls on the
data controller, regardless of whether the
staff responsible for its detection and notification fail to comply with the
measures stipulated in their own protocol and in the EDPB Guidelines 09/2022
by unduly delaying notification, as happened in the
present case on several occasions. This is especially true given that Article
33.4 of the GDPR allows for phased notification of the breach, in the
sense explained above.
Furthermore, the fact that the time limit begins
to run on April 13, 2023, does not preclude the possibility that, upon being informed the
following day, the Data Protection Officer (DPO) may not have sufficient time to assess
and determine that the breach should have been notified within 72 hours
of the aforementioned April 13, 2023. The DPO had two more days to
make the notification, the deadline for which was April 16, 2023, at 6:00 p.m., but did not do so until April 19, 2023.
3. B) Lack of proportionality, infringement of Article 33 of the GDPR.
- The respondent argues that the imposed sanction lacks
proportionality since the Company is being penalized for
having notified the breach, which is unacceptable, given that what is being sanctioned in this case is the failure to comply with the notification deadline
contained in the aforementioned provision, as it has been proven that
the company exceeded the maximum period for notifying the breach by more than
72 hours.
Therefore, it has been proven that a late or
untimely notification occurred, which is an infringement of the obligation stipulated in Article
33 of the GDPR, which this agency must attribute, by application of the Principle
of Legality. Had the breach not been reported, the applicable penalty would have been higher.
28001 – Madrid 6 sedeagpd.gob.es 129/173
This conduct would have been more
reprehensible than late notification.
It should be clarified that the Legal Basis for determining the amount of
the penalty imposed for non-compliance with Article 33 of the GDPR
states that, in setting the amount of €100,000, it was taken into consideration
that the breach was reported, although the notification was
late, and that the number of hours by which the deadline was exceeded when setting
the amount of the fine. Therefore, the same
penalty could not be imposed in any case had the breach not been reported, or had the notification been made later.
The respondent also states that although the notification was made
outside the 72-hour period, the breach was indeed reported, providing all
the information required by Article 33 of the GDPR. Despite this, a fine of €100,000 has been
imposed for a delay of, in this case, forty
eight hours, which is considered disproportionate. In this regard, it should be noted
that the late notification amounted to 72.19 hours, not 48 hours, and
the interpretation made by the proposed resolution should be upheld,
considering that €100,000 is a sanction commensurate with the seriousness of the
conduct, given that the maximum fine is €10 million
or 2% of CECOTEC's annual turnover. And to insist that
late notification is reprehensible and should be subject to sanctions, since
notifying a breach late reduces the supervisory authority's ability to react and protect those affected if necessary, such as
for example, ordering that the breach be communicated to those
affected, so they are prepared for, for example, any
fraud and can react to protect themselves.
- Regarding the claim that “it should be considered that the breach has affected
993 people, with no harm having materialized to the
interested parties, since the company itself made inquiries and it has been
verified that the database was not purchased; therefore, there would be
only one third party (the cyber attacker) who accessed the data.” It is worth
reiterating, once again, that the absence of harm has not been proven, nor
that access to the exfiltrated data by someone other than the cyber attacker did not occur. And that the infringement of Article 33 of the GDPR is
committed by failing to notify the supervisory authority of the breach within the established timeframe,
in which all persons whose personal data
were being processed by the platform whose level of
protection was inadequate to the risk situation they faced are considered affected,
and not only those affected by the breach of 5-4-23.
- Alternatively, the respondent argues that the infringement that, in its
case, would have occurred is not that provided for in Article 76.2 of the LOPDGDD,
but rather the minor infringement of Article 74 m) of the LOPDGDD: “the notification
of incomplete, late, or defective information to the data protection authority
28001 – Madrid 6 sedeagpd.gob.es 130/173
regarding a personal data breach
in accordance with the provisions of Article 33 of the
Regulation (EU) 2016/679”.
Regarding this matter, it should be clarified that the GDPR does not contain a
classification of types of infringements as minor, serious, and very serious, and that the
classification in Articles 72 to 74 of the LOPDGDD is solely
for the purpose of calculating the limitation periods.
In this case, from the initial agreement to initiate these
disciplinary proceedings, it has been considered that the limitation period is, indeed, the 1-year period established for “incomplete,
late, or defective notification” in Article 74.m) of the LOPDGDD, calculated
from the date on which the notification period ended (April 16, 2023, at
6:00 p.m.). Without such prescription having occurred, because
the prescription period was interrupted when the present sanctioning procedure was initiated
on April 1, 2024, and the aforementioned initiation agreement was notified to
the respondent on April 11, 2023, in accordance with the provisions of
Article 75 of the LOPDGDD, which establishes the following:
“Article 75. Interruption of the prescription period for the infringement.The statute of limitations will be interrupted by the initiation, with the knowledge of the
interested party, of the sanctioning procedure, restarting the
statute of limitations period if the sanctioning file is suspended for
more than six months for reasons not attributable to the alleged offender.”
- Finally, the respondent requests that the
infraction be considered subsidiarily as minor and that the sanction be reduced, equating this case to
the sanctions that have been imposed in other previous cases by
this Agency.
Specifically, it mentions two cases:
or “Case EXP202307460 against ‘Dental cuadros’, which analyzes the
security breach that occurred on April 20, 2023,
which was reported to the Agency on May 12, 2023,
affecting 2,500 patients of a dental clinic. In this case, the
Agency determined that the infringement of Article
74 m) of the LOPDGDD was applicable and imposed a fine of five thousand euros (€5,000),
given that it considered the processing of special category data to be an aggravating factor.
Comparing this situation with the one we are
concerning in the present case, both the number of affected parties and the
type of data, as well as the number of days the deadline was exceeded,
favor CECOTEC, and yet the penalty is much higher. Therefore,
subsidiarily, it must be understood that there would have been an infringement of Article 74 m) of the LOPDGDD, and the
28001 – Madrid 6 sedeagpd.gob.es 131/173
fine amount should be reduced to five thousand euros.”
Likewise, in PS/00179/2020 against AIR EUROPA, in which
a security breach is also assessed and a penalty is imposed for
an infringement of Article 33, a fine of €100,000 is applied due to a
41-day delay in notification.”
This allegation is also inadmissible, since:
(i) The respondent again makes the same mistake of comparing
this matter with other previous cases, assessing the
number of individuals affected by the breach, which affects the classification of
the concurrent result-based infringements, instead of the
potential number of affected individuals whose personal data was on the
platform, which is the number that should be assessed in risk-based infringements
such as this one, as explained above.
(ii) Furthermore, the respondent erroneously interprets that this Agency has classified this
infringement as minor in other cases, unlike the present one,
which is not true, as also indicated above.
(iii) With regard to EXP202307460 against ‘Dental cuadros’, the
claimant failed to consider that this company had
a much lower turnover than CECOTEC (€517,290 in 2022 compared to over €105 million for CECOTEC), turnover being a
starting point that must be considered for
the determination of the penalty, in accordance with the
District Fines Guide (EDPB Guidelines 04/2022).
(iv) And with regard to PS/00179/2020 against Air Europa, in which a breach notification was filed 41 days late,
it should be noted that the decision was issued on March 15, 2021,
before the EDPB's Guidelines 09/2022 on breach notifications and the Fines Guide approved
by EDPB Guidelines 04/2022 had been adopted. Therefore, the legal situation
existing at that time is not comparable to the current one.
It should be noted that in the specific case in question, the breach
began days before the GDPR came into force (when these obligations became
enforceable). And in the present case,
the breach occurred on April 5, 2023 (almost five years after the entry
into force of the GDPR, when the Guidelines
for notifying breaches had already been approved and the criteria for calculating
fines had been established by the EDPB), and we are faced with an infringement
whose effects may have permanent and irreversible consequences for
the rights of the data subjects, given that the database was put
up for sale to the highest bidder on the dark web.
28001 – Madrid 6 sedeagpd.gob.es 132/173
FIFTH.– Lack of need to notify the data subjects at
the time of the breach. Infringement of Article 34 of the GDPR.
- In order to avoid redundancy, the arguments presented in previous submissions are reiterated,
which implies that it continues to maintain that there was no high
risk and therefore it has no duty to report the breach. And it is specified that the
total number of affected parties is 993, not one thousand, nor one million, which, as
has already been stated, is not a matter of dispute but rather acknowledged by the proposed
resolution, which in no way excludes the duty to communicate the breach to
these 933 affected parties, but rather confirms it. In response to these arguments, we can
reiterate the answer given in the proposed resolution to which
reference has been made in the previous Legal Basis, confirming
that there is no doubt that in this case the requirements
of Article 34 of the GDPR are met—and specifically the high risk that the respondent denies—
which determine that it is mandatory to communicate the breach to the 933 affected parties who
have been confirmed throughout the investigation, and acknowledged by the
respondent.
- Furthermore, CECOTEC points out that it disagrees with the statement
made in the proposed resolution (page 93) that “it has not been possible to identify the malicious actor and the database has been for sale
on a dark web forum since April 5, 2023,” since: (i) the truth is that an investigation was carried out (…) by the Company, after which it concluded that no activity or purchase had been detected and that “there is no evidence
of any harm to the interested parties” (page 7 of the Resolution); (ii) moreover, the attacker has been identified, as the Agency itself contacted
him and provided his contact information through INCIBE (pages 22, 30, and 50 of the Resolution).
This statement—made in the proposal to respond to the
claimant's allegations that the plaintiff had not been
identified and that this agency had not provided him with his information in order to
contact him, as the inspector in the proceedings did—is not a relevant
issue in this case to determine whether there is an obligation to report
the breach to the affected parties or any of the other alleged violations in
these proceedings.
However, for the sake of clarity, it should be noted that the
statement in question was not made in the terms suggested by the
claimant, since: (i) the claimant again assumes that the statement
made on page 7 of the proposal was an admitted fact therein,
when it was merely a summary of the claims made by the
claimant in the background section; (ii) and it must also be clarified that when in FD 3.1 on “Acknowledged Facts”, the phrase mentioned
28001 – Madrid 6 sedeagpd.gob.es 133/173
referred to whether the contact details
of the malicious actor (email address) were known from the outset, and not to whether the actor's identity was identified
as is clearly deduced from the literal wording of this
fragment of the proposal, which stated the following: “In its second written
submission of allegations (CECOTEC), it states that it filed a complaint after learning from
this Agency that the cyber-attacker had been contacted during the
investigation phase, at which point it was able to obtain the contact details of the
malicious actor. However, the fact is that these same details, which the
inspector used to contact the actor during the investigation, were found in the
first communication from INCIBE received by the respondent, which also
provided the link to access the publication and suggested contact
the cyber-attacker.”
VI.
Breach of the Principle in Article 5.1.f) GDPR.
The principles relating to processing are, on the one hand, the starting point and the closing clause
of the legal framework for data protection, constituting true
rules informing the system with a strong expansive force; on the other hand, by
having a high level of specificity, they are mandatory rules that are susceptible
to being infringed.
Article 5.1.f) “Principles relating to processing” of the GDPR establishes the Principle of
protection of the confidentiality and integrity of personal data, in the following terms:
“1. Personal data shall be: f) processed in a manner which ensures appropriate security of the personal data, including protection against
unauthorized or unlawful processing and against accidental loss, destruction or damage,
by implementing appropriate technical or organizational measures (“integrity and confidentiality”).”
This Principle imposes on the controller of any personal data processing the
obligation to prevent unauthorized or unlawful processing of such data. In other words, a controller must not process personal data of its customers if it is not
in a position to guarantee the confidentiality and integrity of said data and prevent
a third party from accessing data that does not belong to it. For this very reason, a business activity involving the management of data exceeding one million clients, such as that carried out by the accused entity (table ***TABLE.1 alone, the target of the cyberattack, contained more than two million records), requires special due diligence to prevent this type of access.
However, the duty to guarantee the confidentiality of personal data is not limited to preventing a third party from accessing this personal data without authorization, but extends to preventing them from knowing and decrypting this personal data, from exposing it by publishing it, and from transferring it to third parties.
28001 – Madrid 6 sedeagpd.gob.es 134/173
In other words, it is understood that the diligence required of the data controller under Article 5.1.f) of the GDPR to comply with their duty of confidentiality regarding personal data extends not only to the duty to provide the necessary measures to prevent unauthorized access by third parties (such as that which occurred in this cyberattack), but also to establish appropriate measures for the pseudonymization and encryption of personal data, carrying out a proper information encoding process to prevent it from being disclosed and reaching unauthorized persons. Therefore, in cases of
cyberattacks such as this one, encryption and pseudonymization prevent
unauthorized processing from taking place, since even if the cyberattacker
manages to steal personal data, they will not be able to access it because it is unintelligible due to
encryption, and will not be able to make subsequent illegitimate use of it. This
encryption obligation is therefore essential to fulfilling the duty of
confidentiality imposed on the data controller.
In this regard, Recital 75 of the GDPR refers to the risks to the rights and freedoms of individuals that arise in these situations:
“The risks to the rights and freedoms of natural persons, of varying severity and likelihood, may arise from the processing of data that could cause physical, material or non-material damage, in particular where the processing may lead to discrimination, identity theft or fraud, financial losses, damage to reputation, loss of confidentiality of data subject to professional secrecy, unauthorized reversal of pseudonymization or any other significant economic or social harm; where data subjects are deprived of their rights and freedoms or prevented from exercising control over their personal data; where the personal data processed reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, and the processing of genetic data or data concerning health.” or data concerning sexual life, or criminal convictions and offenses or related security measures;
in cases where personal aspects are assessed, in particular the analysis or
prediction of aspects related to work performance, economic situation,
health, personal preferences or interests, reliability or behavior, location or
movements, for the purpose of creating or using personal profiles; in cases where
personal data of vulnerable persons, in particular children, are processed; or
in cases where the processing involves a large amount of personal data
and affects a large number of data subjects.”
In the present case, according to the first four proven facts of this Resolution, it is established that:
- A breach of confidentiality occurred involving the personal data contained in the table “***TABLE.1: addresses and clients” of the former CECOTEC online store platform, as a result of a cyberattack by a malicious actor who posted an advertisement for the sale of the data extracted from said platform on a dark web forum dated April 5, 2023, as referred to in the first proven fact. This breach was reported by INCIBE on the same day and communicated to the company on several occasions until the company detected the personal data breach and notified this Agency.
28001 – Madrid 6 sedeagpd.gob.es 135/173
- It has been confirmed that the malicious actor was able to illegitimately access the
information contained on said platform, and that they have at least
a total of 1,000 records included in the table “***TABLE.1: addresses and
clients” of CECOTEC, corresponding to 933 people included
in the sample that the latter provided to the inspector of the preliminary
proceedings dated August 4, 2023, which was added to the
proceedings dated November 2, 2023.
- As stated in the Record of February 14, 2023, attached to the
present proceedings - a copy of which was sent to the respondent along with the
proposed resolution - once the data from sample 2 was compared with the
data included in table ***TABLE.1, whose content The entire data was provided by
CECOTEC on September 24, 2023. There is no doubt about the absolute match between
the 24 fields and the 1,000 records included in both lists (sample and table),
with even the 4 types of database identifier codes being identical.
Therefore, it has been established beyond a doubt that the cyber attacker was able to access this personal data illegitimately. This is acknowledged
by the defendant herself in her arguments against the proposed resolution, as
stated in the fourth proven fact.
- It has not been possible to determine the entry vector that enabled the
cyberattack. Therefore, no responsibility is imputed to the defendant for not
having adopted the appropriate organizational and technical measures to prevent
the cyber attacker from accessing the platform and exfiltrating this personal data. As detailed in Legal Grounds III through V,
although there is a high probability that the entry point that enabled
the exfiltration of personal data by the cybercriminal was the lack of
platform updates since 2019, and the existence of a critical vulnerability
in 2022 published by the software manufacturer, for which
an update was released to fix the vulnerability but was not downloaded
by the defendant; the fact is that there is insufficient evidence
to establish this causal link between the existence of
uncorrected vulnerabilities and deficiencies in the platform hosting the
data and the exfiltration carried out as a result of the cyber incident.
However, it has been proven that the company responsible for processing acted negligently in breaching the confidentiality of the exfiltrated personal data, since it has been proven that the personal data contained in the two samples provided by the malicious actor (in the advertisement and in the sample subsequently provided to the inspector) had not been encrypted or pseudonymized.
Regarding this matter, although the defendant claims to have adopted encryption measures on the backups hosted on Amazon and on the data communication protocols in its submissions to the proposed resolution, it has not been proven that it applied encryption measures to the database at rest where the accessed and exfiltrated personal data was stored, nor to the servers or devices where the exfiltrated personal data was stored. And yet, it is established
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 136/173
that the personal data exfiltrated from table
***TABLE.1 of the platform had not been encrypted or pseudonymized at
the source (at rest) before exfiltration, since all the
exfiltrated personal data appearing in sample 2 of 1000 records that was
provided by the malicious actor to the inspector are readable and intelligible.
In short, it follows from everything stated above that it has been proven during the investigation
that the cyber attacker has access to part of the content of a CECOTEC database (at least, the personal data of the 933 individuals with valid ID cards
who appeared in the sample provided to the inspector in this case, unencrypted and unpseudonymized). This implies that the risk of loss of confidentiality of the
personal data to which the database was subject has materialized, since
(i) on the one hand, there has been a leak or usurpation of the personal data referred to above, with a third party gaining
illegitimate access to it, and being able to know its entire content, given that
it had not been encrypted by CECOTEC; (ii) Furthermore, this misappropriation of personal data has allowed the cyber attacker to use it for purposes not authorized by its owners (sold, disclosed, published, exploited for other uses, etc.), all without the owners' consent.
Therefore, it has been established in this case that the breach of confidentiality has resulted in a total and absolute loss of control over the personal data by its owners and the data controller. Worse still, since the data has been available for sale since April 5, 2023, there is a very high risk of fraudulent use (identity theft, fraud, financial losses, etc.) or of its use for any other purpose that, under certain circumstances, could constitute a threat to its owners. It should also be noted that most of the leaked personal data is data that cannot be modified or replaced (name, surname, national identity document number, address, etc.).
This loss of control over one's own personal data translates into a violation of the fundamental right to data protection recognized in Article 18.4 of the Spanish Constitution, as the Constitutional Court has indicated (Judgment 292/2000, of November 30, 2000): “the fundamental right to data protection aims to guarantee individuals the power to control their personal data, its use and purpose, in order to prevent its illicit and harmful trafficking, which would violate the dignity and rights of the data subject (...),” given that the right to data protection guarantees individuals the power to dispose of their data, which can only be in the hands of persons authorized by a legal basis provided for in data protection regulations.
Therefore, it is understood that CECOTEC is responsible for the
commission of an infringement of Article 5.1.f), dismissing the allegations made
by the company in this regard for the reasons stated in
Legal Grounds IV and V of this Proposal, given that:
- As stated in the response to the allegations made by
CECOTEC, in this case the company is considered guilty of
failing to fulfill its duty to protect the confidentiality of the personal data that
was exfiltrated, not because the cyber attacker was able to access and exfiltrate
28001 – Madrid 6 sedeagpd.gob.es 137/173
the personal data contained in the aforementioned table ***TABLE.1 of its former
online store platform, but because it has been demonstrated that it had not
applied the necessary encryption and pseudonymization processes
to personal data that would have rendered them unintelligible for
those who do not have the decryption key.
Encryption that would not have prevented the cyber attacker's unauthorized access to personal data,
but would have prevented the breach of confidentiality,
since it would have prevented the attacker from understanding (and therefore knowing)
its content, as well as using it, disseminating it to third parties, and/or
publishing it online, as has indeed happened in this case, where
it is recorded that the database was offered for sale on a dark web forum
on April 5, 2023.
- Regarding the principle of double jeopardy (ne bis in idem), since no allegations were made
in the proposed resolution against the arguments presented in response
to the allegations against the initial agreement (in response to the first allegation
formulated by the accused in legal basis IV), it can be understood
as confirmed that there is no violation of the principle of double jeopardy (ne bis in idem) in this case, nor should the rules on concurrent sanctions be applied. Therefore,
the rule provided for in Article 29 of the LRJSP cannot be applied, since
the data controller has failed to comply with two
different obligations, engaging in two negligent acts (in this
case, omissions). Thus, we are faced with two different
obligations incumbent upon the controller, the omission of which violates the
legally protected interests in two different provisions:
- The omission of the duty to encrypt and pseudonymize the data provided for in
Article 5.1.f) of The GDPR constitutes negligent conduct that violates the
obligation to protect confidentiality as provided for in Article 5.1.f) of the GDPR.
- And the omission of the remaining organizational and technical measures of the platform
as established in the eighth finding of fact of this proposal
violates the duty to maintain the security of the platform as provided for in
Article 32 of the GDPR.
Furthermore, it cannot be said that “the same conduct is being punished twice,” since
the omission of the duty to encrypt personal data will only be
considered to impute negligent conduct on the part of the data controller in the
commission of the infringement of Article 5.1.f) of the GDPR, and not to impute negligent conduct in the commission of the infringement of Article 32 of the GDPR, which
is justified by the failure to adopt the remaining organizational and
technical security measures referred to in the eighth finding of fact.
Therefore, as already stated, the Principle of Absorption invoked by the defendant cannot be applied,
since we are dealing with a case of
"plurality of actions" or actual concurrence of offenses, and not a case of
"concurrence of offenses" or medial concurrence of offenses, in accordance with the
provisions of the Guidelines approved by the EDPB, which have been referenced
above (Guide to Fines).
28001 – Madrid 6 sedeagpd.gob.es 138/173
Consequently, following the investigation, the proven facts are considered to constitute an infringement of Article 5.1.f) of the GDPR, for failing to adopt the necessary mechanisms and measures to guarantee the confidentiality of the personal data that was exfiltrated in the cyber incident published on April 5, 2023.
It has been established that the defendant had not adopted the appropriate technical encryption and pseudonymization measures to protect the confidentiality of the personal data contained therein in the event of an unauthorized exfiltration of personal data such as this one, preventing the unauthorized third party, despite having access to the data, from being able to access its content, publish it, exploit it for other purposes, disseminate it, and transfer it to third parties, as it was encrypted and unintelligible.
VII.
Classification of the infringement of Article 5.1.f) GDPR
The infringement of the Principle contained in Article 5.1.f) of the GDPR is classified in Article 83.5 a) of the GDPR, which states that:
“4. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to EUR 20,000,000, or, in the case of an undertaking, up to 4% of its total worldwide annual turnover of the preceding financial year, whichever is higher:
a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43.”
For its part, the LOPDGDD, in its Article 72, for the purposes of the statute of limitations, classifies the following as:
“Very serious infringements:
“Very serious infringements: 1. In accordance with the provisions of
Article 83.5 of Regulation (EU) 2016/679, infringements that constitute a substantial breach of the articles mentioned therein, and in particular the following, are considered very serious and will be subject to a three-year statute of limitations:
1. The processing of personal data in violation of the principles and safeguards established
in Article 5 of Regulation (EU) 2016/679.”
VIII.
Sanction for non-compliance with Article 5.1.f) GDPR
In order to establish the applicable administrative fine, the provisions contained in Articles 83.1 and 83.2 of the GDPR must be observed, which state:
“1. Each supervisory authority shall ensure that the imposition of administrative fines
under this Article for infringements of this
Regulation referred to in paragraphs 4, 5 and 6 is, in each individual case,
effective, proportionate and dissuasive.
28001 – Madrid 6 sedeagpd.gob.es 139/173
2. Administrative fines shall be imposed, depending on the circumstances of each individual case, as an additional measure to, or in lieu of, the measures provided for in Article 58(2)(a) to (h) and (j). When deciding on the imposition of an administrative fine and its amount in each individual case, due consideration shall be given to:
(a) the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned,
as well as the number of data subjects affected and the level of damage they have suffered;
(b) the intentionality or negligence of the infringement;
(c) any measures taken by the controller or processor to remedy the damage suffered by the data subjects;
(d) the degree of responsibility of the controller or processor,
taking into account the technical or organizational measures they have implemented pursuant to Articles 25 and 32;
(e) any previous infringements committed by the controller or processor;
(f) the degree of cooperation with the supervisory authority with a view to remedying the infringement and mitigating its possible adverse effects;
(g) the categories of personal data affected by the infringement;
(h) how the supervisory authority became aware of the infringement, in particular whether and, if so, to what extent the controller or processor notified the infringement;
(i) where the measures referred to in Article 58(2) have been previously ordered against the controller or processor concerned in relation to the same matter, compliance with those measures; (j) adherence to codes of conduct pursuant to Article 40 or to approved certification mechanisms pursuant to Article 42, and
(k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits obtained or losses avoided, directly or indirectly, through the infringement.
(k) In relation to point (k) of Article 83.2 of the GDPR, the LOPDGDD, in its Article 76, "Sanctions and corrective measures", establishes that:
"2. In accordance with the provisions of Article 83.2(k) of Regulation (EU) 2016/679, the following may also be taken into account:
a) The continuing nature of the infringement.
b) The connection between the infringer's activity and the processing of personal data.
c) The benefits obtained as a result of committing the infringement.
d) The possibility that the data subject's conduct could have induced the commission of the infringement.
e) The existence of a merger by acquisition subsequent to the commission of the infringement, which cannot be attributed to the acquiring entity.
f) The impact on the rights of minors.
28001 – Madrid 6 sedeagpd.gob.es 140/173
g) Having, when not If mandatory, a data protection officer must be appointed.
h) The controller or processor must voluntarily submit to alternative dispute resolution mechanisms in cases where disputes arise between them and any data subject.
In this case, considering the seriousness of the infringement, and especially the consequences for data subjects, a fine is warranted.
The fine imposed must be effective, proportionate, and dissuasive in each individual case, in accordance with Article 83.1 of the GDPR. To guarantee these principles, the status of the accused party as a large company and its turnover are considered beforehand.
In accordance with the aforementioned provisions, once the investigation of the procedure has been carried out, for the purpose of determining the amount of the penalty to be imposed in this case for the infringement defined in Article 5.1.f) of the GDPR, as defined in Article 83.5.a) of the GDPR, for which the company is held responsible, the following criteria for determining the severity of the penalty are deemed applicable:
1. Article 83.2.a) GDPR: “the nature, seriousness, and duration of the infringement, taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered.”
As stated in Legal Grounds III and IV of this
Proposal, the initial agreement established the “initial sanction” based on a number
of 6 records of real people that the company CECOTEC acknowledged and
acknowledges as affected by the leak, since prior to the investigation
it had only been verified that the cyber attacker possessed the 17
records corresponding to 6 people, which were included in the first sample
published by the cyber attacker in the advertisement.
However, following the investigation, it has been established through the
evidence contained in the fourth finding of fact of this proposal, that the
cyber attacker had unauthorized access to a total of 1,000 records
corresponding to a total of 933 individuals identified
with a valid National Identity Document (DNI), after DNI validation was performed and
it was verified that all these records were and exactly matched
those included in table ***TABLE.1: customer and order addresses, which was
provided by CECOTEC during the testing phase. This number
of affected individuals is not disputed in the arguments against the proposed resolution
submitted by the data controller.
Regarding the nature of the personal data affected, it should be noted that the leak refers to the following types of personal data
appearing in the sample of 1,000 records provided to the inspector, according to the Excel spreadsheet attached to Annex I of the
28001 – Madrid 6 sedeagpd.gob.es 141/173
Proceedings of February 13, 2025, are as follows:
o Postal address 1 (indicating street, number, postal code, and city).
o Identifying codes: address code, country code, and the
customer, supplier, and manufacturer codes.
o First and last name
o National Identity Document (DNI) number.
o Landline and mobile phone numbers.
Therefore, the proposed resolution suggested increasing the amount of the penalty,
in light of these proven facts. However, as indicated above in legal basis V, the claim
made by CECOTEC regarding the increase in the amount of the fine based on the number of affected parties is upheld.
Regarding the duration of the infringement, it must be considered that the personal data
were put up for sale on the dark web on April 5, 2023,
and are still being sold, without it being possible
to determine the date on which the effects of the leak will cease, which is
indefinite.
2. Art. 83.2b) “the intent or negligence in the infringement.”
Although it cannot be understood that the entity acted with intent, it is observed that
there is a degree of serious negligence on the part of the entity in complying with the
obligations imposed on it by data protection regulations, since,
as already pointed out in response to the allegations made, it is understood that there is negligent conduct on the part of the company, for not having applied
the necessary encryption and pseudonymization measures to its
personal database, servers, and devices, which would not have prevented
the cyberattacker from illegitimately accessing, extracting, or
exfiltrating the data, but would have prevented the breach of
data confidentiality from occurring, since if the data had been encrypted, the
cyberattacker would not have been able to know its content, decrypt it without having the
key, and therefore, not use, publish, or transfer it to third parties.
However, for the purpose of determining the amount to be imposed for the negligent act,
gross negligence is considered to exist only with respect to the
omission of these encryption and pseudonymization measures, as it has not been
proven that negligence occurred in failing to adopt the measures that
could have prevented the cyberattack. Therefore, the imposed penalty is lower
than it would have been if it had been proven that
both negligent acts or omissions of measures occurred.
In this regard, the judgment of the National High Court of 17/10/2007 can be cited, which, although issued
before the GDPR came into effect, is perfectly
applicable to the case under analysis. The judgment, after alluding to the fact that entities whose activities involve the continuous processing of customer and third-party data must maintain an appropriate level of diligence, specified that “(...) the Supreme Court has consistently held that negligence exists whenever a legal duty of care is disregarded, that is, when the offender does not act with the required diligence. And in assessing the degree of diligence, special consideration must be given to the professionalism of the individual, and there is no doubt that, in the case now examined, when the appellant's activity involves the constant and extensive handling of personal data, the rigor and meticulous care to comply with the relevant legal provisions must be emphasized” (Article 83.2, b) of the GDPR).
3. “The activity of the allegedly infringing entity is linked
to the processing of personal data of both clients and
third parties” (Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k).
The processing of personal data is essential to the activity of the accused entity,
given that its corporate purpose is the wholesale trade of
household appliances and electronic devices through online store management platforms.
This data pertains to clients, suppliers, and employees of the company
under investigation. Therefore, the significance of the conduct that is the subject of this
complaint is undeniable.
Consequently, based on the available evidence and considering the company's
turnover, a fine of €140,000 is imposed for the commission of an infringement of Article 5.1.f) of the GDPR.
IX.
Non-compliance with the obligation under Article 32 GDPR
Furthermore, and regardless of the duty to guarantee the confidentiality of personal data provided for in Article 5.1.f) of the GDPR, any data controller that manages personal data databases of its clients, employees, or suppliers with internet access, as is the case with the company that is the subject of this procedure, is also obliged to adopt procedures that include appropriate technical and organizational measures to ensure that these personal data databases have a level of security appropriate to the risk, which includes the possibility of cyberattacks, theft of personal data, or identity theft, among others.
Specifically, it is Article 32 of the GDPR, “Security of processing,” that establishes this obligation:
“1. Taking into account the state of the art, the costs of implementation, and the nature, scope, context, and purposes of processing, as well as the risks of varying likelihood and severity for the rights and freedoms of natural persons, the controller and the processor shall implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, which may include, among other things:
(a) the pseudonymization and encryption of personal data;
28001 – Madrid 6 sedeagpd.gob.es 143/173
(b) the ability to ensure the ongoing confidentiality, integrity, availability, and resilience of processing systems and services;
(c) the ability to restore the availability of and access to personal data in a timely manner in the event of a physical or technical incident;
(d) a process for regularly testing, assessing, and evaluating the effectiveness of the technical and organizational measures organizational measures to ensure the security of the processing.
2. When assessing the adequacy of the level of security, particular consideration shall be given to the risks presented by the processing of data, in particular as a result of the accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to, personal data transmitted, stored, or otherwise processed.
3. Adherence to an approved code of conduct pursuant to Article 40 or to an approved certification mechanism pursuant to Article 42 may serve as evidence of compliance with the requirements laid down in paragraph 1 of this Article.
4. The controller and the processor shall take measures to ensure that any person acting under the authority of the controller or the processor and having access to personal data may only process such data on instructions from the controller, unless required to do so by Union or Member State law.
It should be noted that the GDPR does not establish in the aforementioned provision a list of the
security measures that must be applied according to the data being processed, but rather establishes that the controller and the processor
must implement technical and organizational measures appropriate to the risk involved in
the processing, taking into account the state of the art, the costs of implementation, the
nature, scope, context, and purposes of the processing, and the risks of likelihood
and severity for the rights and freedoms of data subjects.
That is, in accordance with the Principle of proactive responsibility that underpins the
regulation contained in the GDPR, the controller must assess all concurrent risks and determine, on their own and under their own responsibility, which
security measures are appropriate for the specific processing being carried out.
In other words, the lack of a general list of measures to be
adopted in the GDPR does not exclude the obligation to have all necessary measures available and functioning correctly.
To guarantee these security factors, appropriate technical and organizational measures are necessary.
These protective measures must be suitable and proportionate to the identified risk. This implies conducting a risk analysis prior to processing. When assessing
the adequacy of the level of security to the risk, particular consideration will be given to the
risks presented by the data processing in question, in the sense expressed
in Recital 83 of the GDPR, which states that:
28001 – Madrid 6 sedeagpd.gob.es 144/173
“In order to maintain security and prevent processing from infringing the provisions of
this Regulation, the controller or the processor shall assess the risks
inherent in the processing and implement measures to mitigate them, such as encryption. These
measures shall ensure an appropriate level of security, including
confidentiality, taking into account the state of the art and the cost of their
implementation in relation to the risks and the nature of the personal data
to be protected. When assessing the risk in relation to data security,
consideration shall be given to the risks arising from the processing of personal data,
such as the accidental or unlawful destruction, loss, or alteration of personal data
transmitted, stored, or otherwise processed, or the unauthorized communication or
access to said data, which could particularly cause
physical, material, or immaterial damages.”
In this case, we begin with a specific situation involving the coexistence of two
online store management platforms for customers, suppliers, and employees of the
company under investigation, which was not properly implemented from the perspective of
protecting the personal data that continued to be managed on the
old platform.
Regarding this, the company states:
“The platform was replaced by a new, internally developed online store that adopted more modern, open-source web development technologies. The decision to close the original platform in favor of the new solution was based on the limitations that the ***SOFTWARE.1 system began to show in relation to the growing demands of modern e-commerce. This transition was completed in early 2021. Despite the closure of the original platform, limited access to it (its ***INTERFACE.1) has been maintained for the sole purpose of addressing requests, needs, and/or complaints from the company's customers.”
As stated in the second finding of fact of this proposal, it has been established
in this case that CECOTEC had been processing the
personal data contained in the online store platform ***SOFTWARE.1 1.6
to provide e-commerce services via web services since 2016
(according to its own statements), and has continued processing
the same data to date, although it has made various changes to the
processing, which, moreover, are not documented in its RAT (Regulations for the Use of Personal Data), but it has not
adapted the processing to the new obligations that arose with the entry
into force of the new GDPR on May 25, 2018, whose approval represented a paradigm shift that exponentially strengthened the guarantees of data subjects, with the
consequent imposition of obligations on those responsible for processing
personal data.
Therefore, it is established that:
- The processing of personal data began in 2016, and when the new GDPR came into force, it failed to adapt the processing of personal data contained on said platform to the new obligations arising therefrom, which were applicable from May 25, 2018. All the documents submitted to this procedure were submitted after 2021 and 2022.
28001 – Madrid 6 sedeagpd.gob.es 145/173
Therefore, despite being mandatory, it did not analyze the risks to the rights and freedoms of data subjects to determine whether a Data Protection Impact Assessment (DPIA) was necessary, nor did it adopt the security measures referred to in Article 32 of the GDPR, nor did it approve an adequate protocol for managing personal data breaches that was communicated to all staff. All the
documents provided date from 2021 (Security Incident Management Protocol) or 2022 (Risk Analysis, Staff Training Measures, etc.), and their requirements do not comply with legal obligations.Having corrected some of these breaches following the cyberattack
through the corrective measures documented in the ninth finding of fact
of this Proposal.
- It should also be noted that the breach worsened when the
new online store was implemented in early 2021, from which
a new platform was created for new customers acquired from
2021 onwards, but the decision was made not to migrate the data contained in the
old platform to the new one, thus eliminating its exposure on the internet. This migration
CECOTEC indicated was “planned for the coming months” during the
investigation phase, without having made any further statements on the matter,
beyond stating that it has disabled its internet access, without indicating what has
happened to the personal data stored therein.
Thus, in its Response #2, CECOTEC states that when it created the new
online store platform starting in January 2021, it chose to maintain the
processing of personal data contained on the old but
limited platform (…) keeping the personal data of its customers,
suppliers, and manufacturers generated between 2016 and 2020 stored on this old platform, which is perfectly possible. However, there is evidence in the
proceedings that the lack of migration of personal data to the new
platform was not accompanied by the necessary updates and guarantees that
would ensure that the platform that remained operational was properly
protected.
- Indeed, and as a result of the checks carried out by the cybersecurity officer on the platform, to verify the veracity of the
cyberattack, it has been confirmed that on the date the breach was detected
(April 14, 2023, according to the email provided as Annex 6), the platform
suffered from the vulnerabilities indicated in the eighth finding of fact of
this Proposal. That is, version 1.6 of the platform where the leaked personal data was located
was based on an obsolete and
outdated version of the software ***SOFTWARE.1, with known
vulnerabilities in both its ***SERVICE.2 and ***SERVICE.1, which had been unsupported
since 2019, and whose administration section
(***SERVICE.1) was publicly accessible via the internet (although restricted by
username and password). Furthermore, it was revealed that as of the date of
detection of the breach (April 14, 2023), the
organizational and technical security measures on said platform, as detailed in the
aforementioned proven fact, had not been adopted.
28001 – Madrid 6 sedeagpd.gob.es 146/173
This platform continued to manage more than 2 million
records with personal data at that time (table “***TABLE.1” provided during the
testing phase alone contained a total of 2,057,313 records, which are reduced to
2,054,164 records with a mobile phone number). And that, having remained in
these conditions in January 2021, it was left without adequate
protection to guarantee the traceability, availability, confidentiality,
integrity, and authenticity of the personal data contained therein.
Specifically, as explained in Legal Basis Three of this
resolution, regarding the organizational and technical measures that were
in place at the time of the cyberattack and before the security breach was detected to
guarantee the security of the personal data contained in the former CECOTEC online store platform
***SOFTWARE.1 (referred to as
preventive measures in the API report), it is established in the eighth finding of fact of
this Proposal that:
- The platform was only equipped with the preventive measures that
CECOTEC reported and documented during the investigation phase of these
proceedings: which the inspector included in his API report.
(…)
- It has been detected that the platform suffered from the following deficiencies and
version vulnerabilities, which were necessary to protect the security of
the platform, and therefore, mandatory for the data controller in accordance with the provisions of Article 32 of the GDPR.
This refers to the finding that vulnerabilities existed that
affected ***SERVICE.1 and ***SERVICE.2, that the platform was
outdated and unsupported since 2019, and that it had internet access (with
a username and password).
All of these were acknowledged by the cybersecurity manager in the
email of April 14, 2023, highlighted by CECOTEC in their Response #2, and
verified by the inspector through the Official Report of November 2, 2023.
As has been pointed out on several occasions, although it has not been proven
that these were the origin or entry point of the cyberattack, their omission
should be penalized because it constitutes a breach of Article 32 of the GDPR.
- Furthermore, it has also been verified that the following
necessary measures to guarantee a level of security appropriate
to the risk had not been adopted:
Lack of adequate measures to guarantee traceability of the
platform: Those related to the logs, the lack of monitoring, and the lack
of access control for platform users, as detailed in
the eighth proven fact.
Lack of updating of the platform's Risk Analysis.
28001 – Madrid 6 sedeagpd.gob.es 147/173
The file shows that the company did not carry out an adequate
risk analysis prior to the initial processing in 2013, nor after the
entry into force of the GDPR in May 2018, nor prior to the modification
undergone by the platform in 2021.
The final report of the risk analyses for the rights and
freedoms of the individuals affected by the processing activities
related to the breach (customers) provided by the company is dated April
10, 2022, when the processing of customers' personal data
began in 2013, according to the RAT, or in 2016, according to the company.
In addition to being late, this 2022 risk analysis does not consider
all the concurrent risks with the diligence required of a
data controller responsible for a database of more than 2 million records.
Among other things, it analyzes the risks of processing
customer and supplier data; HR management and recruitment together in a confusing manner, without independently specifying the
risks corresponding to each type of processing affected, nor adequately grading
their level of severity.
This risk analysis has also not been updated after detecting the
vulnerabilities revealed by the incident. The company states in its letter of August 18, 2023, that: “The Spanish Data Protection Agency (AEPD) is informed that, in the last year, the position of Data Protection Officer has been held by three different people, resulting in a lack of
continuity in the functions of the Data Protection Officer
specified in Article 39 of the Regulation Regulation (EU) 2016/679 of 27 April 2016 (hereinafter, “GDPR”). Therefore, the company is currently
undergoing an urgent review of
documents and deciding on measures to be taken and procedures to be
implemented, including a review of all risk analyses
performed and an assessment of the need to conduct an
impact assessment of these risks.
It also notes that a Security Committee was established on 14 September 2023 with the objective of reviewing documents and adopting corrective measures. However, to date, the company
has not provided a new risk analysis compliant with the GDPR, nor has it
assessed whether it is necessary to conduct an impact assessment under the
terms stipulated in Article 35 of the GDPR. Despite having
stated in its submissions to the initial agreement of May 2024
its intention to do so in the coming months, the submissions to the
proposed resolution submitted On March 18, 2025, they made no mention of this matter.
• Lack of approval and implementation of a Security Breach Management Protocol
in accordance with regulations.
28001 – Madrid 6 sedeagpd.gob.es 148/173
According to the evidence contained in the proven facts
eighth and ninth of this proposal, it is deduced that as of the date of detection
of the breach (April 13, 2023), the company had not fulfilled its obligation
to establish procedures that would allow for the prompt detection and
communication of this type of alert within its organization,
in accordance with the provisions of the “Guide for the notification of personal data breaches” published by this Agency, and the provisions of the
Guidelines of the European Data Protection Board (hereinafter,
EDPB), the highest European authority on the matter.
Thus, the EDPB Guidelines 01/2021 on examples of
notification of personal data breaches, adopted on 14 January
2021, state that: “11. All controllers and processors
must have plans and procedures in place to deal with
potential data breaches. Organizations
must have clear hierarchies and designated individuals responsible for
specific aspects of the recovery process.”
And as elaborated in section II of Guidelines
WP 250 on notification of personal data breaches of 3 October
2017: “Article 32 makes it clear that the controller and the
processor must have appropriate technical and
organizational measures in place to ensure an adequate level of
security of personal data: the ability to detect, address
and notify a breach in a timely manner should be considered an
essential element of these measures.”
As stated in the ninth finding of fact, before detecting the
breach, CECOTEC submitted to the proceedings a Security Breach Management Protocol dated July 31, 2023,
updated on August 29, 2023, which was prepared
after receiving the first investigation request made
by this Agency, and should be understood as adopted as a corrective measure.
Before the breach was detected on April 13, 2023, only one Security Incident Management Protocol dated April 22, 2021, was approved
which was not
signed, and did not comply with the requirements of the
applicable regulations, according to the EDPB Guidelines referenced
above. The company has not demonstrated
that this 2021 protocol was known and applied by its
personnel, as no proof of its publication or
communication to staff has been provided.
Furthermore, the evidence in the proceedings indicates that
the 2021 Protocol was not correctly applied by the staff
responsible for detecting the breach of 5/4/23, since: (i) the first
INCIBE cyber incident alert was received on 5/4/23 in the general mailbox
but was not forwarded to those responsible for detecting and managing the
breach, as the protocol stipulated; (i) Nor was it applied by the
cybersecurity officer and the DPO who intervened in the
28001 – Madrid 6 sedeagpd.gob.es 149/173
detection, analysis, and response to the breach, since they
were unaware that the protocol indicated that it was sufficient to have
sufficient certainty that a breach might have occurred, and
both understood that it was necessary to have absolute certainty
that the exfiltration of all the data that the cyber attacker claimed to have had taken place
in order to require notification to the
agency and communication to those affected, as can be seen from the
communications submitted to the proceedings and the DPO's own
statements made in the report submitted to the
proceedings.
Furthermore, the company states in its documents of August 30 and September 18, 2023, and in its submissions to the initiation agreement, that it has adopted new
measures to strengthen the platform's security following the incident to which the breach refers. These new measures are described as corrective measures in the ninth proven fact, and are as follows:
- After detecting the breach, the corrective measures that the inspector has documented in his API report were adopted:
(…)
- After learning of the initiation of preliminary investigative actions, the company approved a Security Breach Protocol on July 31, 2023, updated on August 29, 2023, which it submitted along with its Response #2.
- Subsequent to the initiation of this case on April 1, 2024,
the investigating officer verified, through a procedural act dated June 3, 2024, that
access to the platform via the internet had been disabled. However,
the arguments against the initiation agreement state—but without providing any evidence or
details—that the processing of personal data contained on this platform has ceased.
And despite reference being made to this
lack of evidence in the proposed resolution, the respondent still has not
provided evidence of having ceased the processing of personal data
in its arguments against the proposal. Therefore,
the cessation of processing cannot be considered proven; only the disabling of the online platform has been deemed
proven.
The adoption of these corrective measures, which undoubtedly should have been implemented earlier, demonstrates that the responsible party failed to consider the risks involved in maintaining the ***INTERFACE.1 platform, which was outdated, lacked support, and lacked adequate security measures. Since it is
undoubted that some of these measures should have been foreseen from the beginning of the platform's
processing in 2016, and others from the start of the migration to the
new platform, partially closing the old one in 2021.
In conclusion, in light of the facts established during the investigation phase, it can be confirmed that – even if a loss of
confidentiality or leakage of personal data due to a cyberattack, as
has occurred in this case, had not materialized – the company would be liable for having
seriously breached the obligation stipulated in Article 32 of the GDPR with respect to
the personal data contained on this platform, given that it has been proven that
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 150/173
there was a near-total lack of an adequate procedure establishing appropriate technical and organizational security measures adopted to guarantee an adequate level of security. to the risk related to, among other issues mentioned, the personal data
contained on its online store platform. It was also established that the company had not conducted an adequate risk analysis that reflected the risks arising from the processing, analyzed their impact, and
anticipated appropriate measures to mitigate, reduce, or avoid them.
X.
Classification of the infringement of Article 32 GDPR
The infringement of Article 32 of the GDPR is classified in Article 83.4(a) of the GDPR as follows:
“4. Infringements of the following provisions shall be subject, in accordance with paragraph 2, to administrative fines of up to EUR 10,000,000, or, in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher:
(a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43.”
For its part, the LOPDGDD, in its Article 73, for the purposes of the statute of limitations, classifies the following as:
“Serious infringements:
In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679, the following infringements are considered serious and will be subject to a two-year statute of limitations:
a substantial breach of the articles mentioned therein, and in particular,
the following: f) The failure to adopt the appropriate technical and organizational measures to ensure a level of security appropriate to the risk of the processing, as required by Article 32.1 of Regulation (EU) 2016/679.”
XI.
Penalty for non-compliance with Article 32 GDPR
In accordance with the provisions transcribed in legal basis VIII (Articles 83.1 and 2 of the GDPR, and 76 of the LOPDGDD), in this case, considering the seriousness of the infringement found, and paying particular attention to the consequences that its commission has on the data subjects, a fine is warranted.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, as established in Article 83.1 of the GDPR. To guarantee these principles, the status of the defendant as a large company and its turnover are taken into consideration beforehand.
Once the procedural investigation has been carried out, for the purpose of determining the amount of the
penalty to be imposed in this case for the infringement classified under Article 32 of the
28001 – Madrid 6 sedeagpd.gob.es 151/173
GDPR, classified under Article 83.4 of the GDPR for which the
company is responsible, the following criteria for determining the severity of the penalty are considered applicable:
1. Article 83.2.a) GDPR. “the nature, seriousness and duration of the infringement,
taking into account the nature, scope or purpose of the
processing operation concerned, as well as the number of data subjects affected and the
level of damage suffered.”
Regarding the seriousness of the infringing conduct, the following should be considered as aggravating factors:
the high number of deficiencies or
vulnerabilities detected on the platform, and the lack of
organizational and technical measures adopted by the company
regarding the personal data on the platform to guarantee a level of
security appropriate to the risk, with the ultimate aim of protecting the rights
and freedoms of the natural persons whose data was contained therein,
failing to conduct an adequate analysis of the processing risks involved, their impact, and the measures and safeguards that needed to be adopted
to guarantee a level of security appropriate to the risk of the personal data
processed on this platform.
Likewise, the infringement of Article 32 of the GDPR is considered particularly serious in this case, given that the database contained on the platform held more than two million records (in its table “***TABLE.1” alone, which is the one provided by the accused company) and contained personal data such as address, national identity document number, tax identification number, telephone number, and other fields of the data subjects already referenced in the Proceedings of February 13, 2025.
Therefore, considering that the lack of adequate measures affected the entire personal data database contained on the platform, it is understood that this infringement jeopardized the rights and freedoms of a very large number of the entity's clients, employees, and suppliers by failing to thoroughly analyze the risks and adopt the appropriate technical and organizational measures to guarantee their security in accordance with the new requirements of the GDPR.
And in this case, the seriousness of the infringement is also assessed by considering
the very high number of affected individuals, since
the defendant states that table ***TABLE.1 alone contained data
on more than 2,052,000 people, whose personal data was placed
at risk since at least 2016, without adapting to the new requirements
of the GDPR, which mandated risk management and analysis, and the adoption of
the measures referred to in Article 32 of the GDPR. This risk
increased exponentially in 2019 when the contract for support and platform updates was discontinued, and again in 2021 when the
SERVICE.2 of the platform was shut down, as already mentioned. Therefore, the
duration of the ongoing infringement is more than 6 years (between the entry into force of the GDPR and the present, during which all the necessary corrective measures to adapt the processing to the GDPR have still not been adopted).
28001 – Madrid 6 sedeagpd.gob.es 152/173
2. The degree of intent or negligence in the infringement of Article 83.2.b)
of the GDPR.
Although it cannot be considered that the defendant acted with intent
or malice, it is confirmed that there was a very serious lack of diligence, classified
as gross negligence, in compliance with the obligation established by
Article 32, which left the personal data contained on the online store platform
in a state of almost complete lack of protection. The level of
non-compliance is such that we can speak of a systemic violation, of a
almost complete lack of procedure regarding the establishment and
adoption of appropriate technical and organizational security measures,
for the reasons stated in response to the allegations in Legal Basis V.
Regarding the possibility of sanctioning the lack of due diligence, we refer
once again to what was indicated in the Judgment of the National Court of 17/10/2007.
3. The activity of the allegedly infringing entity is linked
to the processing of personal data of both clients and
third parties.
In the activity of the accused entity, the processing of personal data is essential, given that its corporate purpose is the wholesale trade of household appliances and electronic devices through online store management platforms.
The data of the investigated company's clients, suppliers, and employees is therefore undeniable, and the significance of the conduct that is the subject of this complaint is undeniable (Article 76.2.b) of the LOPDGDD in conjunction with Article 83.2.k).
For the purposes of deciding on the imposition and amount of the fine, in accordance with the investigation carried out, taking into account the criteria for determining the severity of the penalty under Article 83.2 of the GDPR, as previously mentioned, and the respondent's turnover, with respect to the infringement committed by violating Article 32 of the GDPR, it is considered that the respondent should be fined €750,000 (Seven hundred and fifty thousand euros).
XII.
Failure to comply with the obligation under Article 33 of the GDPR.
Once a personal data breach has occurred, the data controller is obligated to notify it in accordance with the terms and conditions set out in
Article 33 of the GDPR on “Notification of a personal data breach to the supervisory authority,” which states:
“1. In the event of a personal data breach, the controller shall notify the competent supervisory authority in accordance with Article 55 without undue delay and, where feasible, no later than 72 hours after becoming aware of it, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons. If notification to the supervisory authority cannot be made within 72 hours, it must be accompanied by an indication of the reasons for the delay.
2. The processor The supervisory authority shall notify the controller without undue delay of any personal data breaches of which it becomes aware.
3. The notification referred to in paragraph 1 shall, at a minimum:
(a) describe the nature of the personal data breach,
including, where possible, the categories and approximate number of data subjects concerned, and the categories and approximate number of personal data records concerned;
(b) communicate the name and contact details of the data protection officer or other contact point where further information can be obtained;
(c) describe the likely consequences of the personal data breach;
(d) describe the measures taken or proposed by the controller to address the personal data breach, including, where appropriate, measures to mitigate its possible adverse effects.
4. Where and to the extent that it is not possible to provide the information at the same time, the information shall be provided in stages without undue delay.
5. The data controller shall document any personal data breach, including the facts relating to it, its effects, and the corrective measures taken. This documentation will enable the supervisory authority to verify compliance with the provisions of this article.
As explained in Legal Basis IV and V, in response to the
allegations made by the company, in this case it has been proven that
a breach of confidentiality occurred involving personal data contained in one of
the tables on CECOTEC's former online sales platform, which
affected at least 933 individuals whose data was included therein.
There is sufficient evidence that the conditions of Article 33 of the
GDPR are met, which require notification of the breach to this supervisory authority, since a “personal data breach” has occurred, and it is likely that the breach poses a risk to the rights
and freedoms of natural persons.
In this case, the company notified this Agency of the personal data breach on April 19, 2023, but not within the terms and timeframes required by Article 33 of the GDPR, which states that the data controller was obligated to notify this supervisory authority of the personal data breach “without undue delay and, where feasible, no later than 72 hours after it became aware of it.”
* ... From the analysis of the emails provided by the company as Annexes 6 and 7
of the statement of allegations dated December 30, 2023, and the Data Protection Officer's (DPO) Incident Analysis Report
28001 – Madrid 6 sedeagpd.gob.es 154/173
attached as Annex 3 to the same document, the following chronology of events regarding the detection and notification of the breach emerges:
The cybersecurity incident alert in a CECOTEC database
was first detected and communicated to the company by INCIBE via
an email sent on April 5, 2023, at 2:53 p.m., the same day
that the malicious user posted on a dark web forum announcing
that they had a database belonging to a Spanish company that could
correspond to CECOTEC. However, the company did not respond to
this email nor begin the checks until it received a second
email from INCIBE at 11:10 a.m. on April 12, 2023,
due to CECOTEC's lack of response, requesting a report on what had
happened with the incident reported on April 5, 2023.
The second breach notification issued by INCIBE on April 12, 2023, was indeed answered.
The cybersecurity manager, lacking the first email, requested its forwarding to INCIBE on April 12, 2023, losing another day
until finally receiving this information from INCIBE on April 13, 2023, even though it had already been provided
in the initial email of April 5, 2023, which was in the company's inbox.
INCIBE resubmitted the information on the same day, April 13, 2023, at 11:10 a.m.,
at which point the company's cybersecurity officer began the
appropriate checks to verify the sample and conduct a security analysis of the
platform, which could be considered the start of the "investigation period
necessary to verify that there is a reasonable degree of certainty of the
breach," as referred to in Guidelines 9/2022, on the notification of
personal data security breaches under the GDPR,
as explained in Legal Basis IV when responding to the
allegations of the data controller.
On the same day, April 13, 2023, at 5:26 p.m., the cybersecurity officer concluded the investigation and informed INCIBE of the following:
“The data shown in the image provided by user
***USER.1 on ***FORUM.1 is test data. Furthermore,
the website containing this data was shut down in 2021 and is no longer operational.
At this time, we cannot determine whether this constitutes a data breach based solely
on the image shown. The reference being discussed is
[***REFERENCE.1]. In any case, we are at your disposal
for anything you may need.”
On April 14, 2023, at 2:31 p.m., an email was sent
from the cybersecurity department to the Data Protection Officer (DPO) of CECOTEC, which has been
transcribed verbatim in the fifth finding of fact, informing her of what
had happened, the responses to INCIBE, and the results of these
investigations. The DPO indicated that she decided to proactively report the breach
because the 17 records affected 6 real individuals.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 155/173
The notification of the personal data breach to this
Agency was not made until April 19, 2023.
As noted in response to the allegations regarding the calculation of the time limit for notifying the breach, there is no doubt that the company acted negligently in notifying the breach:
- First, because it has been proven that they did not have a Breach Management Protocol
compliant with regulations and meeting the requirements of the EDPB Guidelines 09/22 on breach notification,
but rather a 2021 Security Incident Management Protocol, which did not meet the minimum requirements to be considered a Breach Management Protocol.
- And second, because the company did not apply its own 2021 Incident Management Protocol (which regulated how to detect a security incident and
report a breach), and there is no evidence that this protocol was communicated to employees and managers
prior to the breach. As stated in the
file:
That those in charge of the CECOTEC general mailbox did not forward the first cybersecurity incident alert to
those responsible for detecting and reporting the breach.
The 2021 Protocol does not include the
contact information of the individuals to whom this notification should have been sent.
It is on record that the company corrected this deficiency after the incident,
sending an email on April 19, 2023, informing them of the
addresses to which all alerts should be sent, after inquiring
why they had not received the alert of April 5, 2023.
That both the cybersecurity manager and the company's Data Protection Officer (DPO)
were unaware that their Protocol stated that it was not
necessary to know "with certainty" the
entry vector of the cyberattack or whether it had affected all records
in the database to conclude that a personal data breach had occurred. Since the cybersecurity officer denies that
a breach occurred, mistakenly believing that he needed to have
all the records the malicious actor claimed to possess in order to be
certain that a breach had taken place, when he had already
verified that the 17 records contained in the sample published in
the announcement matched those included in table ***TABLE.1 of the
platform, which could be considered “sufficient certainty”
that a breach was likely to have occurred with respect to
these records. Similarly, the DPD noted in its report that the
notification was made proactively, despite not being obligated to do so,
because the cyberattack was not considered credible, since the
28001 – Madrid 6 sedeagpd.gob.es 156/173
cybersecurity officer had not been able to determine with “certainty” that a breach had occurred. It is clear, therefore, that none of
those responsible for the process actually knew
what mechanisms were in place to determine when
a breach should be reported to this Agency. Furthermore, they merely claimed
that they needed a larger sample of records to verify this without
contacting the malicious actor to obtain it—as the inspector
of the procedure did—and they claim to have requested INCIBE to provide them
with more information—when all the alert emails from INCIBE
clearly indicated that for more information they could contact
the malicious actor.
Had an appropriate breach detection and management protocol been applied,
the verification actions that should have constituted the
"brief initial investigation period" referred to in EDPB Guidelines
09/22 should have begun on April 5, 2023, when
the first alert was received. And since the defendant acknowledged that it
realized it had received the second alert on April 12, 2023, there is no doubt
that, at a minimum, the necessary verification investigations should have begun
on April 12, 2023, when the second
reminder was received, without having to wait to receive the INCIBE email again
with said information on April 13, 2023, given that CECOTEC could
retrieve the initial email from its inbox and know all the data
necessary to begin said investigation.
However, despite this undue delay in detecting the breach being established, the fact remains
that the undue delay in starting the investigations proves that the defendant did not
have the appropriate measures in place for detecting, preventing, and mitigating the
effects of potential breaches of this platform, which constitutes a failure to
adopt the organizational and technical measures of Article 32 of the GDPR. However, this does not affect the calculation of the maximum 72-hour period alleged as a violation of Article 33 of the GDPR, the starting date of which has been a disputed fact in the proceedings.
... As noted in Legal Basis III to V, the time limit or
dies ad quo begins when the company “became aware of the breach,” which
means having “a reasonable degree of certainty” that the breach had occurred,
according to EDPB Guidelines 09/22 on breach notification,
which state the following:
“40. It should therefore be clear that the controller is obliged to act upon any initial alert and to
determine whether or not a breach has occurred. This short period
allows for some investigations to be carried out and for the controller
to gather evidence and other relevant details. However,
28001 – Madrid 6 sedeagpd.gob.es 157/173
once the controller has established with a
reasonable degree of certainty that a breach has occurred, if
the conditions of Article 33(1) of the GDPR are met, they must
notify the authorities of control without undue delay and, if possible, within a maximum period of seventy-two hours. If a controller does not act promptly and it is evident that a breach has occurred, this could be considered a failure to notify in accordance with Article 33 of the GDPR.”
In the present case, the “brief investigation period” to ascertain whether there was a reasonable degree of certainty of the breach was deemed necessary, and it concluded upon completion of the cybersecurity department’s investigation and notification of its findings to INCIBE.
According to the established timeline, as indicated in the response to the allegations, it is proven that the investigation necessary to reach a reasonable degree of certainty regarding the breach concluded on April 13, 2023, at 5:26 p.m., when the CECOTEC cybersecurity manager concluded the investigation and informed INCIBE that the sample data matched the content on the CECOTEC platform, given that:
- The last email informing INCIBE of the incident and possible breach was this one, dated April 13, 2023, with subsequent emails being sent to verify a phishing attempt.
- This is acknowledged by the Data Protection Officer (DPO) in the report attached to Response #1, where it states:
“It wasn't until Thursday, April 13, 2023, that INCIBE provided all
the information regarding the potential breach and, therefore, when CECOTEC
became truly aware of this alleged threat.
- When the email was sent to the DPO (April 14, 2023, at 2:31 p.m.), the
cybersecurity department had already concluded these investigations,
and detected the breach (although it was unaware that the coincidence of these
17 records and the existence of these vulnerabilities and deficiencies
implied a reasonable degree of certainty that a breach had occurred).
Since this email included a complete final report to the DPO,
which detailed all the emails exchanged with INCIBE,
it included many other data not reported to INCIBE, acknowledging
all the vulnerabilities and deficiencies detected, and that the sample
matched entirely with the data from table ***TABLE.1.
From reading it, it is clear that all the analyses and
checks whose information is expanded upon had been carried out before
replying to INCIBE on April 13, 2023. Thus, as stated
in the fifth proven fact of this proposal, which transcribes in full
this email:
Multiple references are made to the analyses already carried out in the past (After
performing the analysis, it was seen that the records in the table coincide with those of
28001 – Madrid 6 sedeagpd.gob.es 158/173
the old Cecotec store; After investigating together with the e-commerce and infrastructure department, we were able to see that the records that the attacker has in the database are from 2016 to 2020; We also
tried to see the logs to see the traceability; After analyzing all the
environments, the cybersecurity department cannot determine whether it was due to malware on a workstation or from the web application itself, since at the workstation level we currently do not have (…)…
etc).
And all these analyses or checks are prior to the conclusion
reached by the same, which is the following:
“However, we still do not know for certain what data the attacker has,
and that is why we wrote to INCIBE-CERT that same Thursday, April 13,
2023, at 5:26 PM.”
Consequently, it follows from the actions that the date from which CECOTEC can be considered aware that there was
a reasonable degree of certainty of the breach, having verified
through its cybersecurity department that it had affected
the 17 records contained in the sample published in the announcement (which
affected 6 real people), after concluding its investigations, was April 13,
2023, at 5:26 PM.
Such And as explained in the response to the objections to the proposed resolution,
in Legal Basis V, it is not acceptable that the starting date for the
calculation (dies ad quo) was: a) either April 14, 2023, at 2:31 p.m., when the
cybersecurity director sent an email to the Data Protection Officer (DPO) informing them of the
communications held and the investigation carried out, since it was the previous day that there was sufficient or reasonable certainty that the 17
records matched and this fact was communicated to INCIBE, regardless of the fact that the DPO was not informed in detail until the following day; b) much less
April 17, 2023, regarding which the respondent provides no justification,
since the communication made to INCIBE on that date was limited to
confirming that their email was not a phishing alert.
It will therefore be starting on April 13, 2024, at 5:26 p.m., when the
initial deadline (dies ad quo) for notifying this agency of the breach must be calculated,
applying the rules for calculating deadlines provided for in the European regulation to which the initiation agreement referred (EEC Regulation, EURATOM No. 1182/71, of June 3, 1971).
Having clarified the dies ad quo, or the date on which the deadline for notifying the breach began, we can now address the issue of the rules for calculating deadlines in order to establish the dies ad quem, or the final date on which the maximum 72-hour period for notifying the breach concluded.
28001 – Madrid 6 sedeagpd.gob.es 159/173
With regard to the rules for calculating deadlines, the company started in Their
allegations to the initial agreement contained several erroneous premises that were clarified in
the proposed resolution, without having been challenged by the same in the
allegations subsequently submitted by the same:
- Calculating time limits in working days, instead of in hours as indicated in
Article 33 of the GDPR.
- Applying the rules for calculating time limits provided for in Spanish regulations,
given that, according to Article 30 of the LPACAP itself, these rules are
applicable “unless otherwise provided by law or European regulation,” as
is the case, since there is a European regulation that governs this matter.
- Proposing an incorrect application of the rule provided for in Article 30.6 of the
LPACAP, which states the following: “When a day is a working day in the municipality
or Autonomous Community in which the interested party resides, and a non-working day at the headquarters of the
administrative body, or vice versa, it shall be considered a non-working day in all cases,”
since the April 17, 2023, is not listed as a non-working day in the calendar of non-working days for the purpose of calculating deadlines for the year 2023, which was approved by Resolution of the State Secretariat for Public Administration on December 1, 2022, and includes non-working days at the national level and in each autonomous community.
In the case of deadlines set in hours, and given that the deadline is established in a European Regulation (GDPR), the provisions of Article 3 of Regulation (EEC,
EURATOM) No. 1182/71 of June 3, 1971, which establishes the rules applicable to deadlines, dates, and time limits, may be applied. Article 3 states the following:
“Article 3 of Regulation (EEC) No. 1182/71.
1. If a time limit expressed in hours is to be counted from the moment an event occurs or an act is performed, the hour during which that event occurs or that act is performed shall not be counted as part of the time limit.
If a time limit expressed in days, weeks, months, or years is to be counted from the moment an event occurs or an act is performed, the day during which that event occurs or that act is performed shall not be counted as part of the time limit.
2. Without prejudice to paragraphs 1 and 4:
(a) a time limit expressed in hours shall begin to run at the start of the first hour and shall end at the end of the last hour of the time limit;
(b) a time limit expressed in days shall begin to run at the start of the first hour of the first day and shall end at the end of the last hour of the last day of the time limit;
c) A period expressed in weeks, months, or years shall begin to run at
the first hour of the first day of the period and shall end at the end of the
28001 – Madrid 6 sedeagpd.gob.es 160/173
last hour of the day that, in the last week, the last month, or the last
year, bears the same name or date as the day from which
a period begins to run. If, in a period expressed in months or years,
the last month lacks the day on which the period should expire, it shall end at the end of the last hour of the last day of that month;
d) If a period comprises parts of a month, for the calculation of
these parts, a month shall be considered to consist of thirty days.
3. Periods shall include public holidays, Sundays, and Saturdays,
unless these are expressly excluded or the periods are expressed in
working days.
4. If the last day of a period expressed in any other way, other than in hours, falls on a public holiday, Sunday, or Saturday, the period will end at the end of the last hour of the following business day.
This provision will not apply to periods calculated retroactively from a specific date or event.
5. Every period of two days or more must include at least two business days.
Therefore, the time period is considered to have begun on April 13, 2023, at 5:23 p.m.
(which would be the "event" from which the time period begins to run in hours, according to the aforementioned Article 3 of the Regulations). From the application of this provision, it follows that the time period began to run "at the beginning of the next hour," that is, from 6:00 p.m. on April 13, 2023, and ended at 6:00 p.m. on April 16, 2023, when 72 hours had elapsed.
It is not possible to deduct the hours of public holidays that fell on Saturdays and Sundays,
since the applicable European regulations do not include the concept of non-working hours
as a general rule, stating in Article 3.3 of the aforementioned EEC Regulation that: “
Time limits shall include public holidays, Sundays and Saturdays, unless these
are expressly excluded or the time limits are expressed in working days.”
There is no exception in the present case that would allow the exclusion of
the hours corresponding to Saturday and Sunday from the calculation.
Consequently, despite having made an interpretation favorable to the responsible company,
considering that it was aware of the breach
when the investigations concluded on April 13, 2023 – instead of April 5, 2023, when
the INCIBE alert was received, or April 12, 2023, when the second alert was received, without taking into account
the undue delays that occurred previously and unduly delayed
the start of these investigations and the detection of the breach – the fact remains
that, even so, it can be concluded that the company exceeded the 72-hour deadline for
notifying INCIBE of the breach after the investigations concluded. Since the deadline expired on
April 16, 2023, at 6:00 p.m., and the breach was not reported until April 19, 2023, at 6:19 p.m.
(72 hours and 19 minutes after the deadline expired)
28001 – Madrid 6 sedeagpd.gob.es 161/173
Therefore, following the investigation, it is established that the maximum 72-hour period stipulated in Article 33 of the GDPR for reporting the breach was exceeded in this case. Consequently, it can be confirmed that the company CECOTEC has committed an administrative infringement for violating Article 33 of the GDPR by failing to report the breach within the deadline (doubling the maximum permitted period).
XIII.
Classification of the infringement under Article 33 of the GDPR
Having confirmed the aforementioned breach of the obligation to notify the data protection authority of the breach, as provided for in Article 33 of the GDPR, this constitutes an infringement classified under Article 83.4 of the GDPR, which, under the heading “General conditions for the imposition of administrative fines,” states:
“Infringements of the following provisions shall be sanctioned, in accordance with paragraph 2, by administrative fines of up to EUR 10,000,000 or, in the case of an undertaking, up to 2% of its total worldwide annual turnover of the preceding financial year, whichever is higher:
(a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39, 42 and 43; (...)”
In this regard, the Article 71 of the LOPDGDD, "Infringements," establishes that:
"The acts and conduct referred to in paragraphs 4, 5, and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements."
For the purposes of the limitation period, Article 7(m) “Minor Infringements”
of the LOPDGDD states:
“In accordance with the provisions of Article 83.4 of Regulation (EU) 2016/679, the following infringements are considered minor and will be subject to a one-year limitation period:
substantial breaches of the articles mentioned therein, and in particular, the following:
(m) Incomplete, late, or defective notification to the data protection authority of information related to a personal data breach, in accordance with the provisions of Article 33 of Regulation (EU) 2016/679.
XV.
Sanction for infringement of Article 33 of the GDPR
In accordance with the provisions transcribed in legal basis VIII (Articles 83.1 and 2 of the GDPR, and 76 of the LOPDGDD), in this case, considering the seriousness of
28001 – Madrid 6 sedeagpd.gob.es 162/173
Given the identified infringement, and considering especially the consequences that its commission has on the data subjects, a fine should be imposed.
The fine imposed must be, in each individual case, effective, proportionate, and dissuasive, in accordance with the provisions of Article 83.1 of the GDPR. To guarantee these principles, the status of a large company and the turnover of the party being sued are considered beforehand.
Once the procedural investigation has been carried out, for the purpose of determining the amount of the fine to be imposed in this case for the infringement classified in Article 33 of the GDPR, and classified in Article 83.4 of the GDPR for which the company is responsible, the following criteria for determining the severity of the fine are considered to apply:
1. Article 83.2.a) GDPR. “the nature, severity, and duration of the infringement,
taking into account the nature, scope, or purpose of the processing operation in question, as well as the number of data subjects affected and the level of damages suffered.
To determine the appropriate sanction, it is considered in favor of the responsible company that the breach was reported to this Agency, and against that there was an excess of more than twice the established 72-hour notification period, since the notification period began on April 13, 2023, at 6:00 p.m., concluded on April 16, 2023, at 6:00 p.m.,
but the responsible company did not report the breach until April 19, 2023, at 6:19 p.m.
Likewise, it should be noted that there was reasonable certainty that the detected breach affected a minimum of six real people whose data appeared in the sample published by the malicious actor, but the investigation carried out on April 13, 2023, revealed to deduce that there was a probability
of high risk to the rights and freedoms of individuals, as well as a high
risk that the scope of the breach would be greater, in the event that it
could have been subsequently verified that it was true that the malicious actor
had almost one million records, as claimed in their advertisement, or
more than one million, as stated when they contacted the inspector. And it is not
on record in this case that the investigation was expanded to
verify the scope of the breach and to notify this
Agency of any potential expansion, if applicable.
2. The degree of intent or negligence in the infringement.
Although it cannot be considered that the defendant acted with intent
or malice, a degree of serious negligence is observed in meeting the deadline
for detecting and notifying the breach, it having been proven that the company did not
act with the required diligence for the reasons already set out in
the previous Legal Basis, and developed in detail in
Legal Basis 4.1 when responding to the Allegations made by the
responsible company.
28001 – Madrid 6 sedeagpd.gob.es 163/173
3. The activity of the allegedly infringing entity is linked
to the processing of personal data of both clients and
third parties.
The processing of personal data is essential to the activity of the accused entity, given that its corporate purpose is the sale of household appliances and
electronic devices through online store management platforms for
clients, suppliers, and employees of the company under investigation. Therefore, the
significant nature of the conduct that is the subject of this complaint is undeniable
(Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k).
The assessment of the circumstances contemplated in Article 83.2 of the GDPR and
Article 76.2 of the LOPDGDD, taking into account the business volume of the company
complained against, and considering all the circumstances of The concurrent nature of the offense, with respect to the infringement committed by violating the provisions of Article 33 of the GDPR, allows for maintaining the initial penalty and proposing a penalty of €100,000 (ONE HUNDRED THOUSAND EUROS).
XV.
Non-compliance with the obligation under Article 34 of the GDPR
Article 34 of the GDPR establishes the controller's obligation to "Communicate a personal data breach to the data subject," in the following terms:
"1. Where a personal data breach is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the breach to the data subject without undue delay."
" 2. The communication to the data subject referred to in paragraph 1 of this
Article shall describe in clear and plain language the nature of the personal data breach and shall contain at least the information and measures referred to in Article 33(3)(b), (c), and (d).
3. The communication to the data subject referred to in paragraph 1 shall not be required if
one of the following conditions applies:
(a) the controller has implemented appropriate technical and organizational safeguards and these safeguards have been applied to the personal data affected by the personal data breach, in particular
those which render the personal data unintelligible to any person who is not authorized to access them, such as encryption;
(b) the controller has taken further steps to ensure that the high risk to the rights and freedoms of the data subject referred to in paragraph 1 is no longer likely to materialize;
28001 – Madrid 6 sedeagpd.gob.es 164/173
c) would entail a disproportionate effort. In this case, a public communication or a similar measure will be chosen instead, ensuring that the interested parties are informed in an equally effective manner.
4. When the controller has not yet notified the data subject of the personal data breach, the supervisory authority, after considering the likelihood that such a breach entails a high risk, may require the controller to do so or may decide that one of the conditions mentioned in paragraph 3 is met.
On the other hand, as already indicated above, Recital 75 of the GDPR lists a series of factors or scenarios associated with risks to the guarantees of the rights and freedoms of data subjects.
According to the findings in the sixth finding of fact of this proposal, it is established in the proceedings that the company responsible for processing:
- Detected the breach (became aware of it upon verifying that there was a reasonable degree of certainty that it had occurred) on April 13, 2023, and notified this Agency of the breach on April 19, 2023, but decided that it was not necessary to communicate the breach to the six affected individuals included in the initial sample provided by the malicious actor's advertisement, given that The leak appeared to be implausible and did not pose a high risk.
- Subsequent to the initial agreement, a copy of the file was sent to the defendant, which contained
the sample of 1,000 records that the inspector obtained from the malicious actor.
The defendant acknowledged in their response to the initial agreement that they had been the victim of a cyberattack by this malicious actor. In their response to the proposed resolution, the defendant acknowledged that the breach affected
the 933 individuals whose personal data is contained in this second
sample, in accordance with Annex I of the Proceedings of February 13, 2025.
Both the initial agreement and the proposed resolution detailed the
reasons why communicating with those affected by the breach was deemed mandatory in this case. Specifically, after the investigation was carried out, the proposed resolution detailed the reasons why the defendant
was conducting an analysis erroneous assessment of the risks arising from the breach,
determining that there was a clear probability of high risk, and that the
remaining requirements stipulated in Article 34 of the GDPR were met, making such notification mandatory.
However, in its response to the proposed resolution, the respondent
reiterates and refers to the arguments previously made on this matter, insisting
that notification of the breach is not required because, in its opinion, there is no high risk,
accepting that the number of affected individuals amounts to 933. Therefore, the respondent continues its infringing conduct, since it continues to fail to notify
the affected parties of the breach, thereby increasing the risks generated, even
after being informed of the detailed reasons why the initial agreement and the
proposed resolution considered it necessary, and still necessary, to notify the affected parties of the breach.
28001 – Madrid 6 sedeagpd.gob.es 165/173
As indicated in the response to the arguments presented in
Legal Grounds III and IV, there is no doubt that the obligation to communicate the “personal data breach” to the affected parties existed in this case, since the requirements set forth in
Article 34 of the GDPR are met, namely: (i) that there is a likelihood that a personal data breach has occurred which poses a high risk to the rights and freedoms of natural persons; (ii) and that none of the grounds for exemption from the duty to communicate established in Article 34.3 apply.
Regarding the likelihood that a high-risk personal data breach has occurred,
to avoid unnecessary repetition, we refer to what is indicated in
Legal Ground IV, where the reasons why It is appropriate to dismiss the fifth allegation in AlegAi#1's brief, which referred to this issue, since CECOTEC denies that there is a high risk in this case, stating that:
“CECOTEC initiated the appropriate checks from the moment it became aware of the INCIBE email and contacted them by telephone. Although it initially had doubts about the certainty of the breach, it ultimately notified the Supervisory Authority as it obtained information about it.
In this context, an internal assessment of the “high risk” was carried out based on the objective information available at the time of becoming aware of the breach, based on the factors indicated in Guidelines 9/2022 on the notification of personal data breaches under the GDPR, dated March 28, 2023.
-Regarding the nature, sensitivity, and volume of the personal data: It consisted of incomplete contact information and was not a special category data.” -Regarding the volume of data: Only 6 data points of real people were verified.
-Regarding the ease of identifying the individuals: It was complex, given that the names and surnames of the individuals involved were not included, nor was there any associated documentation.
-Regarding the type of breach: It affected the confidentiality of the data by an unauthorized third party, but not other aspects such as availability and integrity.
-Regarding the severity of the consequences for the individuals: It was considered not serious, given that the data is not of a special category, identity theft is neither automatic nor simple since the names and surnames of those affected were not included, and furthermore, it was not verified.
-Regarding the characteristics of the individuals: They were not vulnerable individuals or minors.
Following this internal assessment and in accordance with the results of the
COMUNICA BRECHA tool provided by the Spanish Data Protection Agency (AEPD), CECOTEC did not
28001 – Madrid 6 sedeagpd.gob.es 166/173
deem it necessary to report the gap.
However, it is understood that the respondent has not carried out an adequate
assessment of the concurrent risk, since it has not taken into account all the concurrent factors for evaluating the existence of this
risk, as referred to in the Article 29 Working Party Guidelines W250, which are not
limited to assessing only the type of data, nor the number of
people affected, as the respondent claims, but also establish
that other factors that have not been taken into account must be assessed, such as
factors related to the ease of identifying the affected individuals
and the severity of the damage that could occur at the time
the breach was detected, which affected 6 real people.
Had a correct assessment been carried out that considered all the concurrent
risk factors, it would have concluded that the breach entailed a
high risk to the rights and freedoms of those affected, which is
especially clear in this case, where the personal data
was for sale on a dark forum web, leaving them exposed to
fraudulent use by third parties.
Therefore, once it was verified on April 13, 2023, that the malicious user had
at least the identifying personal data of these 6 affected individuals, it should have
determined that a breach of personal data confidentiality was
highly probable, and that, since the data was for sale, there was a high
risk to the rights and freedoms of these 6 people. And regardless of
the reality of the cyberattack on the entire database,
it should at least have informed these 6 people without delay, and it did not. And
subsequently, when it learned from this Agency that the malicious actor had
provided a second sample of 1,000 records, which was given to the
respondent upon requesting a copy of the file, it should have carried out the
verification that the investigating officer of the proceedings performed to analyze the
breach and communicate it to the 933 affected individuals. But it did not do so, nor has it
done so even after being notified of the Proposed resolution and the due diligence
of February 14, 2024, which carried out the aforementioned comparison and verification
of data, concluding that the breach had affected 933
people. And to this day, even though it is acknowledged that the breach affected
these 933 people, it continues to maintain that there is no high risk
to their rights and freedoms, and therefore it has no obligation to report
said breach. This constitutes an infringement of Article 34 of the GDPR,
not with intent, but with gross negligence, given that it continues to act
despite knowing that it is acting against the opinion of this Agency.
As has been pointed out, none of the exceptions
to the duty to report the breach to the affected parties provided for in Article 34.3
of the GDPR apply, as indicated in the initial agreement:
28001 – Madrid 6 sedeagpd.gob.es 167/173
The exception in section 34.3.a) does not apply, since, as indicated in the preceding Legal Grounds, it has been proven that the company had not adopted the appropriate protective measures to prevent the breach of confidentiality of the personal data on this platform, which was unencrypted.
The exception in section b) also does not apply, since the measures
subsequently implemented are aimed at ensuring the traceability of the system,
and at detecting or preventing new leaks or security breaches of personal data,
but are not capable of preventing the high
risk of personal data that has already been leaked and is for sale from materializing.
This is compounded by the high risk generated by the fact that it has not been possible
to identify the attack vector by which access to the database was gained due to the lack of adequate monitoring and traceability measures
of the system.
Finally, the exception in section c) does not apply, since it is considered
that notifying the breach to 6 affected parties would not be a disproportionate effort. Nor would it be
disproportionate to require a public communication addressed to
all those affected by the more than one million records contained on the platform.
From all of the above, it follows that, in accordance with the investigation carried out, it has been
proven that the company responsible for the processing failed to comply with the
duty to notify the affected parties of the breach, since it has been proven that
the defendant should have notified a total of 6 people when it became
aware of the breach on April 13, 2023, and extended said notification to a total of
933 people, once it received a copy of the file on April 30, 2023.
Having failed to comply with this duty, it is appropriate to maintain the charge of infringement
of Article 34 of the GDPR, for not having notified the breach to the 933 affected parties
identified in the proceedings, and to impose a greater penalty than the one
initially set based on 6 people affected by the breach, under the terms that will be
set out in Legal Basis XVII of this proposal.
XVI.
Classification of the infringement under Article 34 of the GDPR
Having confirmed that the obligation to notify
the data subjects of the breach under Article 34 of the GDPR has indeed been violated, this constitutes the commission of the
infringement classified under Article 83.4(a) of the GDPR, which, under the heading
“General conditions for the imposition of administrative fines,” stipulates that:
“Infringements of the following provisions shall be sanctioned, in accordance with
paragraph 2, by administrative fines of up to EUR 10,000,000 or,
in the case of an undertaking, up to 2% of its
total worldwide annual turnover of the preceding financial year, whichever is higher:
(a) the obligations of the controller and the processor pursuant to Articles 8, 11,
25 to 39, 42 and 43;”
28001 – Madrid 6 sedeagpd.gob.es 168/173
In this regard, the LOPDGDD, in its Article 71 “Infringements,” establishes that
“The acts and conduct referred to in paragraphs 4,
5 and 6 of Article 83 of Regulation (EU) 2016/679, as well as those that are contrary to this Organic Law, constitute infringements.”
For the purposes of the statute of limitations for infringements, Article 74(ñ) of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights) provides that:
“The remaining infringements of a purely formal nature under the articles mentioned in paragraphs 4 and 5 of Article 83 of Regulation (EU) 2016/679 are considered minor and shall be subject to a one-year statute of limitations, and in particular, the following:
“(ñ) Failure to comply with the duty to notify the data subject of a data breach that poses a high risk to the rights and freedoms of the data subjects, as required by Article 34 of Regulation (EU) 2016/679, unless the provisions of Article 73(s) of this Organic Law apply.”
XVIII.
Sanction for infringement of Article 34 of the GDPR.
In accordance with the provisions transcribed in legal basis VIII (Articles 83.1 and 2 of the GDPR, and 76 of the LOPDGDD), in this case, considering the seriousness of the infringement found, and paying particular attention to the consequences that its commission has on the data subjects, a fine is warranted. This fine will be individual, effective, proportionate, and dissuasive, as established in Article 83.1 of the GDPR. To guarantee these principles, the status of the defendant as a large company and its turnover are taken into account beforehand.
Once the procedural investigation has been carried out, in order to determine the amount of the sanction to be imposed in this case for the infringement classified in Article 34 of the GDPR, and specifically in Article 83.4 of the GDPR, for which the company is held responsible, the following is taken into account: The following criteria for determining the penalty are considered applicable:
1. Article 83.2.a) GDPR. “the nature, seriousness, and duration of the infringement,
taking into account the nature, scope, or purpose of the processing operation concerned, as well as the number of data subjects affected and the level of damage suffered.”
Regarding the seriousness of the infringement, the number of affected individuals who were not notified of the breach is taken into account. These are the data subjects whose personal data breach was confirmed during the investigation of this case, totaling 933 people, instead of the 6
considered when determining the initial penalty established in the initial agreement.
The nature of the personal data affected is also taken into consideration.
It should be noted that the breach refers to the types of data that appear in the sample provided by the malicious actor to
28001 – Madrid 6 sedeagpd.gob.es 169/173
inspector, as referenced in the Proceedings of February 13, 2025. And
the number of concurrent risk factors that
determine the high risk to the rights and freedoms of those affected is also considered, and
especially, the fact that the personal data has not only been
exfiltrated and is in the possession of a malicious user, but also
has been partially disseminated and put up for sale on the dark web.
To determine the penalty, the duration of the infringement is also considered,
considering that the company should have notified the breach to the
affected parties without delay, and at the latest, once it detected that the sample of the
advertisement contained the data of these 6 affected parties. And subsequently, once
it received the initiation agreement and a copy of the file on April 30, 2023, it should have
initiated investigations to determine whether this breach occurred, as
this administration has done, and notified the affected parties. were included
in the sample provided by the malicious actor to the inspector.
This infringement persists to the present and will continue until the
notification is sent to them.
2. Article 83.2b) of the GDPR: “Intentionality or negligence in the infringement.”
Although the respondent cannot be considered to have acted with intent
or malice, a serious lack of diligence is observed in compliance with the
obligations imposed by data protection regulations,
since it is on record that the company noticed that 6 records in the
sample matched, and yet, they decided not to report it due to a manifestly incomplete
risk assessment. After receiving the initiation agreement
which included this corrective measure, they decided not to comply. Furthermore,
upon receiving a copy of the file, they did not take the
necessary steps to verify and report this breach, and upon receiving
the proposed resolution rejecting the allegations based on
the respondent's assertion that there was no duty to communicate, continues
maintaining the same.
Regarding the possibility of sanctioning the lack of diligence, we refer
once again to what was indicated in the Judgment of the National Court of 10/17/2007.
3. The activity of the allegedly infringing entity is linked
to the processing of personal data of both clients and
third parties.
In the activity of the accused entity, the processing of personal data is essential
because its corporate purpose is the sale of household appliances and
electronic devices through online store management platforms of
clients, suppliers, and employees of the company under investigation, so the
significance of the conduct that is the subject of this complaint is undeniable
(Article 76.2.b) of the LOPDGDD in relation to Article 83.2.k).
The balance of the circumstances contemplated in Article 83.2 of the GDPR and
Article 76.2 of the LOPDGDD, considering the volume of business of the company
28001 – Madrid 6 sedeagpd.gob.es 170/173
The claim, regarding the infringement committed by violating the provisions of
Article 34 of the GDPR, allows for increasing the fine initially set in
the initial agreement of €40,000 and imposing a fine of €100,000 (ONE HUNDRED THOUSAND EUROS).
XV.
Adoption of Corrective Measures
Once the commission of the four alleged infringements has been confirmed, the controller must be required to adopt appropriate measures to bring its actions into compliance with the regulations mentioned herein, in accordance with Article 58.2(d) of the GDPR, which states:
“Each supervisory authority may require the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specific manner and within a specified time frame (...)”.
The imposition of this measure is compatible with the administrative fine, as provided for in Article 83.2 of the GDPR.
In this regard, the following corrective measures are agreed upon, pursuant to
Article 58.2.d) of the GDPR:
o To demonstrate to this Agency, within one month, that the accused entity has
notified the affected data subjects whose data has been compromised by the cyberattack, in accordance with the terms and conditions
provided for in Article 34 of the GDPR.
o To demonstrate to this Agency, within seven months, compliance with the following security measures, pursuant to Article 32 of the
GDPR:
1. Update of the Risk Analysis Report of October 2022,
by preparing a document containing a comprehensive analysis that
identifies all risk factors or threats to the rights and
freedoms of the platform targeted by the cyberattack, and assesses the level of individual and overall risk
in order to determine what measures and safeguards
would be necessary to mitigate the impact of the risks.
2. If the new risk analysis determines that a Data Protection Impact Assessment (DPIA) of the processing is necessary, provide proof that it has been carried out and successfully completed, ensuring that its content complies with the requirements of Article 35 of the GDPR.
3. Provide documentary evidence that all necessary organizational and technical measures have been adopted to guarantee a level of security appropriate to the risks presented by the data processing, in accordance with the new risk analysis and, where applicable, the DPIA.
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es 171/173
Please be advised that failure to comply with any order to adopt measures imposed by this agency in the sanctioning resolution may be considered an
administrative infringement in accordance with the GDPR, specifically classified as an
infringement in Articles 83.5 and 83.6, and may lead to the initiation of
further administrative sanctioning proceedings.
Therefore, in accordance with applicable legislation and having assessed the criteria for
graduating the sanctions whose existence has been proven, the Presidency of
the Spanish Data Protection Agency RESOLVES:
FIRST: To IMPOSE on CECOTEC INNOVACIONES, S.L.U., with Tax Identification Number B97937890,
for committing the 4 administrative infringements of the GDPR, the following
administrative fines:
o For the infringement of Article 5.1.f) of the GDPR, classified in Article 83.5 of the
GDPR, a fine of €140,000.
o For the infringement of Article 32 of the GDPR, classified in Article 83.4 of the
GDPR, a fine of €750,000.
For the infringement of Article 33 of the GDPR, as defined in Article 83.4 of the GDPR, a fine of €100,000.
For the infringement of Article 34 of the GDPR, as defined in Article 83.4 of the GDPR, a fine of €100,000.
This totals €1,090,000 (ONE MILLION NINETY THOUSAND EUROS).
SECOND: That the Presidency of the Spanish Data Protection Agency order CECOTEC INNOVACIONES, S.L.U., with Tax Identification Number B97937890, to demonstrate, pursuant to Article 58.2.d) of the GDPR, that it has complied with the corrective measures set forth in Legal Basis XVIII of this Resolution:
or to demonstrate to this Agency, within one month, that the accused entity has notified the personal data breach to the affected parties whose data has been affected by the cyberattack, in accordance with the terms and conditions stipulated in Article 34 of the GDPR.
or Demonstrate to this Agency within 7 months compliance with the following security measures, in accordance with Article 32 of the
GDPR:
1. Update the Risk Analysis Report of October 2022,
by preparing a document containing a comprehensive analysis that
identifies all risk factors or threats to the rights and
freedoms of the platform targeted by the cyberattack, and assesses the level of individual and overall risk
in order to determine what measures and safeguards
would be necessary to reduce the impact of the risks.
2. If the new risk analysis requires
a Data Protection Impact Assessment (DPIA) of the processing, demonstrate that it has been carried out and successfully completed,
28001 – Madrid 6 sedeagpd.gob.es 172/173
ensuring that its content complies with the requirements of
Article 35 of the GDPR.
3. Provide documentary evidence that all necessary organizational and technical measures have been adopted to guarantee a level of security appropriate to the risks presented by the data processing, in accordance with the new risk analysis and, where applicable, the DPIA.
THIRD: NOTIFY A.A.A. of this resolution.
FOURTH: COMMUNICATE this resolution to the Ombudsman, in accordance with Article 77.5 of the LOPDGDD.
FIFTH: This resolution will become enforceable once the deadline for filing an optional appeal for reconsideration (one month from the day following notification of this resolution) has expired without the interested party having exercised this right.
The sanctioned party is advised that they must pay the imposed sanction once this resolution becomes enforceable, in accordance with Article 77.5 of the LOPDGDD. 98.1.b)
of Law 39/2015, of October 1, on the Common Administrative Procedure of Public Administrations (hereinafter LPACAP), within the voluntary payment period established in Article 68 of the General Collection Regulations, approved by Royal Decree 939/2005, of July 29, in relation to Article 68. 62 of Law 58/2003, of December 17,
by depositing the fine, indicating the Tax Identification Number (NIF) of the sanctioned party and the procedure number shown in the heading of this document, into the restricted account IBAN: ES00-0000-0000-0000-0000-0000 (BIC/SWIFT Code: CAIXESBBXXX), held in the name of the Spanish Data Protection Agency at CAIXABANK, S.A.
Otherwise, collection will be pursued during the enforcement period.
... Upon receipt of the notification and once it becomes enforceable, if the enforceability date falls between the 1st and 15th of each month, inclusive, the deadline for making a voluntary payment will be the 20th of the following month or the next business day thereafter. If the date falls between the 16th and the last day of each month, inclusive, the payment deadline will be the 5th of the second following month or the next business day thereafter.
In accordance with Article 50 of the LOPDGDD (Organic Law on the Protection of Personal Data and Guarantee of Digital Rights), this Resolution will be made public once it has been notified to the interested parties.
In accordance with Article 76.4 of the LOPDGDD, and given that the amount of the imposed penalty exceeds one million euros, the information identifying the offender, the offense committed, and the amount of the penalty will be published in the Official State Gazette (Boletín Oficial del Estado).
Against this resolution, which ends the administrative process in accordance with art. 48.6 of the
LOPDGDD, and in accordance with the provisions of Article 123 of the LPACAP, the
interested parties may, optionally, file an appeal for reconsideration with the
Presidency of the Spanish Data Protection Agency within one month from the
day following notification of this resolution, or directly file an
contentious-administrative appeal with the Contentious-Administrative Chamber of the
National Court, in accordance with the provisions of Article 25 and paragraph 5 of
28001 – Madrid 6 sedeagpd.gob.es 173/173
the fourth additional provision of Law 29/1998, of July 13, regulating the
Contentious-Administrative Jurisdiction, within two months from the
day following notification of this act, as provided for in Article 46.1 of the
referred Law.
Finally, it should be noted that, in accordance with Article 90.3 a) of the LPACAP (Law on the Common Administrative Procedure of Public Administrations), a final administrative decision may be provisionally suspended if the interested party expresses their intention to file an appeal with the Administrative Court.
If this is the case, the interested party must formally notify the Spanish Data Protection Agency by submitting a written request through the Agency's Electronic Registry [https://sedeagpd.gob.es/sede-electronica-web/], or through one of the other registries provided for in Article 16.4 of the aforementioned Law 39/2015, of October 1. They must also provide the Agency with documentation proving the effective filing of the appeal with the Administrative Court. If the Agency does not receive notification of the filing of an administrative appeal within two months from the day following notification of this resolution, the precautionary suspension will be terminated.
926-070623
Lorenzo Cotino Hueso
President of the Spanish Data Protection Agency
C/ Jorge Juan, 6 www.aepd.es
28001 – Madrid sedeagpd.gob.es




